secrets-management
Fail
Audited by Snyk on Jun 22, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt includes hardcoded secret values (e.g., VAULT_TOKEN='root', password=secret, "super-secret-password") and examples that pass or echo secrets directly in commands/CI steps, which require including secrets verbatim in output.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill includes runtime-executed external components—GitHub Actions like hashicorp/vault-action@v2 (https://github.com/hashicorp/vault-action) and aws-actions/configure-aws-credentials@v4 (https://github.com/aws-actions/configure-aws-credentials) and Docker images pulled and run such as trufflesecurity/trufflehog:latest (Docker Hub) and vault:latest—which are fetched at workflow/runtime and execute remote code.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata