amz-listing-images

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the skill content for high-entropy literal values that grant access.

Findings:

  • The WhatsApp invite URL "https://chat.whatsapp.com/ILX65p1yWcaIG3c9WGHpTY" contains a 24-character alphanumeric invite token (ILX65p1yWcaIG3c9WGHpTY). This is a high-entropy literal that directly grants access to a chat group, so it meets the "provides access to a service" definition and is treated as a secret (not a documentation placeholder).
  • No API keys, bearer tokens, PEM/private keys, or other high-entropy credentials were found elsewhere in the document.
  • No placeholders, simple setup passwords, or truncated/redacted values were present that would require ignoring.

Therefore I flag the WhatsApp invite token as a secret.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:07 PM
Issues
1
Security Audit — snyk — amz-listing-images