core-context-compressor

Fail

Audited by Snyk on Jul 8, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs the compressor to extract and include configuration values as key-value pairs (e.g., PORT=3000, DB_URL, API_KEY, connection strings), which requires the LLM to handle and potentially output secrets verbatim, creating an exfiltration risk despite a later admonition to avoid including them.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 8, 2026, 12:22 PM
Issues
1
Security Audit — snyk — core-context-compressor