customgpt-api

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). This skill explicitly shows and encourages embedding API keys/Bearer tokens directly in code and curl examples (e.g., API_KEY = "your_api_key", Authorization: Bearer YOUR_API_KEY), which requires the agent to include secret values verbatim in outputs.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill exposes the agent to untrusted third‑party content because it shows adding and syncing external sources (e.g., the "sitemap_path" in the Create Agent example and the /api/v1/projects/{id}/sources and pages endpoints) and returns RAG responses/citations that the agent will read and interpret.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 06:53 AM
Security Audit — snyk — customgpt-api