amz-launch-runway

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the skill content for high-entropy literal values that provide access.

Findings:

  • The WhatsApp invite URL "https://chat.whatsapp.com/ILX65p1yWcaIG3c9WGHpTY" contains an embedded invite token ("ILX65p1yWcaIG3c9WGHpTY") that is a high-entropy string which grants access to a private chat group. This matches the definition of a secret (a literal value that provides access to a service) and is not a placeholder, redaction, or simple example password.
  • No API keys, private keys (PEM blocks), or other high-entropy credentials were present.
  • There are no obvious placeholders or simple setup passwords to ignore.

Therefore I flag the WhatsApp invite token as a secret present in the document.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:08 PM
Issues
1
Security Audit — snyk — amz-launch-runway