cn-futures-terminal
Fail
Audited by Snyk on Mar 24, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The prompt includes example commands that inline TQ_USER and TQ_PASSWORD (e.g., TQ_USER='xxx' TQ_PASSWORD='xxx' bash ...), which encourages the agent to ask for and emit user credentials verbatim into generated commands — an explicit secret-exfiltration pattern.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata