no-slop
Fail
Audited by Snyk on Jul 28, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill explicitly instructs the editor to "leave verbatim spans intact" (quotes, code, etc.) and to edit user-supplied drafts as-is, which means if a draft contains API keys, tokens, or passwords the model is required to reproduce them verbatim in its output, creating an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata