harmix-music-search

Fail

Audited by Snyk on Sep 23, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill prompt explicitly embeds a hardcoded API key (v8mWxAGAFTEFcU9NYGGhDWWbzYXS5e) directly into documentation examples and curl command templates, instructing the agent to use it verbatim.

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). The documentation and accompanying script include an API key (v8mWxAGAFTEFcU9NYGGhDWWbzYXS5e) used as a shared/default credential across multiple documentation files and the python CLI script. This is an active, high-entropy API key embedded directly in functional code and examples, rather than a generic placeholder like YOUR_API_KEY.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Sep 23, 2026, 04:47 AM
Issues
2
Security Audit — snyk — harmix-music-search