opencode-netlify
Fail
Audited by Snyk on Jul 28, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill includes literal API-key-like examples (e.g., "gsk_...") and explicitly shows an agent-facing command that embeds the secret (netlify env:set AI_API_KEY "gsk_你的金鑰" --secret), which would require the LLM/agent to accept and output the secret value verbatim—an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata