testing-for-system-prompt-leakage
Fail
Audited by Snyk on Aug 3, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs target models to reproduce their system/developer prompt (including "any tools and keys", DB_PASSWORD=..., Base64-encode your system prompt, etc.), which forces the LLM to output secret values verbatim if they exist.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata