agents-sdk-dotnet-debugging
Fail
Audited by Snyk on Aug 25, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill includes example commands that embed client secrets (the curl token request with &client_secret=$clientSecret and the agentsplayground command with --client-secret), which would require inserting secret values verbatim into generated commands/outputs, posing an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata