pureclaw-connect
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I scanned the documentation for literal, high-entropy credentials. I flagged the single hardcoded token found in INSTALL.md:
- GATEWAY_TOKEN="mWPzkdOSV37FK0RWKS3YFSbHkaUAYscifD7UyJgvVLXTldyS" — this is a long, random-looking string present verbatim in the docs, which meets the definition of a secret (high entropy, usable credential).
Ignored items and why:
- BACKEND_URL (https://be.paioclaw.ai) — service URL, not a secret.
- PIPEDREAM_* entries — they are placeholders or masked (e.g., proj_xxxxxxx, ), so ignored per placeholders rule.
- Example/placeholder tokens in JSON ("") — explicit placeholders, ignored.
- Sample account IDs (apn_xxxxxxx), channel IDs (C03NA8B4VA9), and simple words like "production" — not high-entropy secrets or clearly documentation examples.
Issues (1)
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata