flask-app-builder
Audited by Snyk on Jun 23, 2026
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt references an "app-registry" file that holds credentials and gives examples that pass an email/password as CLI args (gen_playwright_test.py ), which encourages reading and embedding secret values verbatim in commands or generated outputs.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context via the
/api/chatendpoint, which takesmessagefrom the runtime request body (data.get('message')) and forwards it asmessages=[{'role':'user','content': msg}]to the OpenRouter call—thismessageis authored by an external user of the app.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). I flagged two URLs: the remote widget script (https://ai-agent-widget-production.up.railway.app/widget/AGENT_ID.js) which is loaded and executes third‑party JS in clients at runtime, and the raw GitHub URL (https://raw.githubusercontent.com/Liberty-Emporium/echo-v1/main/scripts/test_.py) shown being downloaded via curl and then run with python3 — both fetch and execute remote code at runtime.
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). Findings and reasoning:
Flagged as secret
- Willie FloodClaim token: "S7LroZDvJSqzJZ304leqwQcxToJXRwF597gszWWarq4"
- Reason: High-entropy, random-looking bearer/token string that appears to be a usable access token. This matches the definition of a secret.
Ignored (not flagged) with explanation
- Willie agent ID: "F5J8yYT6a6GrppjviN6p8w"
- Reason: High-entropy identifier but likely an agent ID (public identifier) rather than a credential that grants access. Agent IDs are commonly non-secret; treating as non-sensitive here.
- Cakely agent ID: "Fx9e5L1JSpqJtjnhl2jLsQ"
- Reason: Same rationale as Willie agent ID — looks like an identifier, not an access token.
- Cakely token: "cakely-sweet-spot-2026"
- Reason: Low-entropy, human-readable string (looks like a name/label), treated as a non-sensitive configuration value.
- Passwords in app registry (e.g., "admin1234", "liberty2026", "sweetspot2026")
- Reason: Low-entropy, simple setup/example passwords. Per rules, ignore documentation/setup passwords and obvious examples.
- Token paths and env references (e.g., "/root/.secrets/github_token", "/root/.secrets/gitlab_token", "/root/.secrets/ecdash_token", KYS_API_TOKEN env var)
- Reason: These are file paths or environment variable names, not literal secret values. Per rules, ignore.
- Railway Deployment ID "2a242085-0f61-406f-8b87-f6e8eaf6ee24"
- Reason: Identifier/UUID for a deployment, not an access credential.
- Namespace ID "130241649"
- Reason: Numeric identifier, not a secret.
Conclusion: one high-entropy, usable token was found (Willie FloodClaim token) and is flagged. All other detected items are either low-entropy examples, identifiers, or file/path placeholders and therefore ignored.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly includes payment gateway integration: "Payments: Stripe (optional, in requirements)" and the common patterns list includes "Stripe checkout + webhook". Those are specific, dedicated payment APIs (payment gateway) rather than generic tooling, so the skill provides explicit financial-execution capability.
Issues (5)
Insecure credential handling detected in skill instructions.
Third-party content exposure detected (indirect prompt injection risk).
Unverifiable external dependency detected (runtime URL that controls agent).
Secret detected in skill content (API keys, tokens, passwords).
Direct money access capability detected (payment gateways, crypto, banking).