ai-audit-trail-larissa-meredith-flister
Fail
Audited by Snyk on Jul 30, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill explicitly tells the agent to "summarise or reproduce the prompts, if provided" and to identify everything input into the tool, which can force the LLM to echo user-provided secrets (API keys, tokens, passwords) verbatim into its output.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The required runtime workflow for “AI Audit Trail Builder” is intake-driven and generates an audit trail from the user-supplied descriptions/prompts/materials (e.g., the user’s pasted internal case summaries and details), rather than reading outsider-authored free text from an external feed/queue without selecting an item.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata