code-recon

Fail

Audited by Snyk on Aug 4, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill explicitly instructs searching for hardcoded secret patterns (e.g., "sk-", "pk_live_", private key headers) and logging/token grep checks, which encourages locating and potentially including secret values verbatim in outputs or reports.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). Skill.md/docs/advanced-techniques.md describe runtime recon steps that can ingest arbitrary outsider-authored text via developer-provided project inputs and captured real traffic (e.g., reading local README/source files and viewing HTTP request/response/error message content with mitmproxy), which an outsider can poison by submitting those files/traffic into the workflow’s input sources.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 4, 2026, 12:30 AM
Issues
2
Security Audit — snyk — code-recon