wechat-miniprogram
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I looked for high-entropy, literal values that could be used as real credentials. The document contains a Base64-looking string "HyVFkGl5F5OQWJZZaNzBBg==" which is explicitly labeled as "用户的 session-key" (user's session_key) and is therefore a secret-like credential (high-entropy, used for signing/decryption). This is not a generic placeholder (e.g., OPENID, APPID) nor a simple example password, so I flag it.
I ignored obvious placeholders and low-entropy samples elsewhere (strings like "xxxx", "xxxxx", "OPENID", "APPID", "wxa..." service IDs in examples, and short example tokens in comments) because they are documentation placeholders or non-sensitive example IDs per the rules.
Issues (1)
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata