wechat-miniprogram

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I looked for high-entropy, literal values that could be used as real credentials. The document contains a Base64-looking string "HyVFkGl5F5OQWJZZaNzBBg==" which is explicitly labeled as "用户的 session-key" (user's session_key) and is therefore a secret-like credential (high-entropy, used for signing/decryption). This is not a generic placeholder (e.g., OPENID, APPID) nor a simple example password, so I flag it.

I ignored obvious placeholders and low-entropy samples elsewhere (strings like "xxxx", "xxxxx", "OPENID", "APPID", "wxa..." service IDs in examples, and short example tokens in comments) because they are documentation placeholders or non-sensitive example IDs per the rules.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 19, 2026, 05:34 PM
Issues
1
Security Audit — snyk — wechat-miniprogram