flask-app-builder

Fail

Audited by Snyk on Jun 23, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt references an "app-registry" file that holds credentials and gives examples that pass an email/password as CLI args (gen_playwright_test.py ), which encourages reading and embedding secret values verbatim in commands or generated outputs.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.85). Outsider free text can enter the LLM context via the /api/chat endpoint, which takes message from the runtime request body (data.get('message')) and forwards it as messages=[{'role':'user','content': msg}] to the OpenRouter call—this message is authored by an external user of the app.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).


HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). Findings and reasoning:

Flagged as secret

  • Willie FloodClaim token: "S7LroZDvJSqzJZ304leqwQcxToJXRwF597gszWWarq4"
  • Reason: High-entropy, random-looking bearer/token string that appears to be a usable access token. This matches the definition of a secret.

Ignored (not flagged) with explanation

  • Willie agent ID: "F5J8yYT6a6GrppjviN6p8w"
  • Reason: High-entropy identifier but likely an agent ID (public identifier) rather than a credential that grants access. Agent IDs are commonly non-secret; treating as non-sensitive here.
  • Cakely agent ID: "Fx9e5L1JSpqJtjnhl2jLsQ"
  • Reason: Same rationale as Willie agent ID — looks like an identifier, not an access token.
  • Cakely token: "cakely-sweet-spot-2026"
  • Reason: Low-entropy, human-readable string (looks like a name/label), treated as a non-sensitive configuration value.
  • Passwords in app registry (e.g., "admin1234", "liberty2026", "sweetspot2026")
  • Reason: Low-entropy, simple setup/example passwords. Per rules, ignore documentation/setup passwords and obvious examples.
  • Token paths and env references (e.g., "/root/.secrets/github_token", "/root/.secrets/gitlab_token", "/root/.secrets/ecdash_token", KYS_API_TOKEN env var)
  • Reason: These are file paths or environment variable names, not literal secret values. Per rules, ignore.
  • Railway Deployment ID "2a242085-0f61-406f-8b87-f6e8eaf6ee24"
  • Reason: Identifier/UUID for a deployment, not an access credential.
  • Namespace ID "130241649"
  • Reason: Numeric identifier, not a secret.

Conclusion: one high-entropy, usable token was found (Willie FloodClaim token) and is flagged. All other detected items are either low-entropy examples, identifiers, or file/path placeholders and therefore ignored.


MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly includes payment gateway integration: "Payments: Stripe (optional, in requirements)" and the common patterns list includes "Stripe checkout + webhook". Those are specific, dedicated payment APIs (payment gateway) rather than generic tooling, so the skill provides explicit financial-execution capability.

Issues (5)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 06:13 AM
Issues
5
Security Audit — snyk — flask-app-builder