amz-coupon-strategy

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I inspected the skill content for high-entropy, literal values that grant access. The only candidate is the WhatsApp invite URL at the end: "https://chat.whatsapp.com/ILX65p1yWcaIG3c9WGHpTY". The trailing token (ILX65p1yWcaIG3c9WGHpTY) is a random-looking, high-entropy string that directly grants access to a private/group resource, so it qualifies as a secret under the definition ("provides access to a service"). It is not a documentation placeholder, setup password, or redacted/truncated value, so it should be flagged.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:07 PM
Issues
1
Security Audit — snyk — amz-coupon-strategy