amz-cash-flow-forecaster-dd7

Fail

Audited by Snyk on May 27, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the full skill prompt for high-entropy literal values that would grant access.

Flagged item:

Ignored items (reasons):

  • Numeric/example values (e.g., "8,000 USD", "4-day transit", "refund rate 8%") are low-entropy examples, not secrets.
  • There are no API keys, bearer tokens, private key blocks, or other obvious credentials present.
  • No documentation placeholders or redacted/truncated secrets were found.

Recommendation: remove or redact the invite link from public skill documentation, or replace it with a non-sensitive sign-up flow or placeholder.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
May 27, 2026, 02:07 AM
Issues
1
Security Audit — snyk — amz-cash-flow-forecaster-dd7