organization-setup

Fail

Audited by Snyk on Jun 17, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly requires the agent to display the org's generated ATProto password verbatim (in a code block) and to pass invite codes/passwords to the create_organization tool, forcing the LLM to handle and output sensitive credentials directly.

MEDIUM W021: Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

  • Hidden Unicode characters detected (1 type(s) found)

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W021
MEDIUM

Hidden or invisible Unicode characters detected (potential obfuscation or prompt injection).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 17, 2026, 05:55 PM
Issues
2
Security Audit — snyk — organization-setup