amz-supplier-negotiation-script

Fail

Audited by Snyk on Jun 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I reviewed the entire skill content for literal credentials. There are no API keys, PEM/private keys, or passwords. However, the document includes a full WhatsApp invite URL (https://chat.whatsapp.com/ILX65p1yWcaIG3c9WGHpTY). That URL contains a high-entropy token which grants direct access to a private group — functionally a usable credential. It is not a placeholder or a redaction, so it meets the definition of a secret that should be treated as sensitive. No other high-entropy secrets were found.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 25, 2026, 01:08 PM
Issues
1
Security Audit — snyk — amz-supplier-negotiation-script