indykite-authzen-kbac
Fail
Audited by Snyk on May 28, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill's examples and request templates show embedding bearer tokens and AppAgent credentials directly into curl headers/commands (e.g., Authorization: Bearer $SERVICE_ACCOUNT_TOKEN, X-IK-ClientKey), which requires inserting secret values verbatim into generated requests/commands and therefore risks secret exposure.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata