sota-mobile
Fail
Audited by Snyk on Aug 5, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The audit instructions require quoting "the offending code/config" as Evidence, which can force the LLM to reproduce literal secrets or API tokens found in code, creating an exfiltration risk.
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.70). The URL https://cdn.example.com/AnalyticsSDK-3.1.0.xcframework.zip is a direct download of a binary framework from a third‑party CDN — binary artifacts delivered outside a verified package registry/CDN are a higher‑risk vector for malware unless their checksum/provenance is explicitly validated.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E005
CRITICALSuspicious download URL detected in skill instructions.
Audit Metadata