winapp-signing

Fail

Audited by Snyk on Apr 29, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill shows and encourages passing PFX passwords directly on the command line (e.g., --password MySecurePassword and default 'password') and includes literal password examples, which requires the LLM to emit secret values verbatim in commands—an exfiltration risk.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill explicitly instructs installing/trusting certificates into the machine Trusted Root store and requires Administrator/elevated privileges, which modifies persistent, system-wide security state.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 29, 2026, 11:06 AM
Issues
2