amz-inventory-management

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the skill for literal high-entropy credentials (API keys, tokens, private keys, or other access strings). The only candidate that meets the definition of a secret is the WhatsApp invite URL near the end:

https://chat.whatsapp.com/ILX65p1yWcaIG3c9WGHpTY

That URL contains a long, non-guessable token and grants direct access to a WhatsApp group, so it functions as an access credential. It is not a documentation placeholder or a simple setup password, so it should be treated as a secret. No API keys, PEM blocks, redaction markers, or other high-entropy secrets were found elsewhere in the document.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:07 PM
Issues
1
Security Audit — snyk — amz-inventory-management