html-slide-builder

Fail

Audited by Snyk on Jun 14, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). 我檢查了文件內容並比對自動檢出的項目。文件中在 multiple locations(references/firebase-config.md 與兩處 Firebase module scripts)明確包含了 apiKey 值: "AIzaSyAYQhNavPSce17XtvDC5xnXyl9iUhW9KjA"。該字串為高熵、典型的 Google/Firebase API key 模式(不是 YOUR_API_KEY 之類的占位符),並且旁邊還有專案識別資訊(teacherstudy-109ef),因此不是範例或簡單示例密碼。依據定義這屬於實際可用的憑證,應視為需移除或輪換的敏感資訊(即便某些 Firebase 客戶端 API key 用途較受限,也不應公開在原始碼倉庫)。

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 14, 2026, 08:48 AM
Issues
1
Security Audit — snyk — html-slide-builder