pp-printing-press-oauth2

Fail

Audited by Snyk on Aug 17, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill's playbook/recall instructions explicitly include a "token" in slots_resolved and require replaying steps with slot substitution, which would force the agent to insert live tokens/credentials verbatim into commands or outputs (an exfiltration risk).

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.70). These point to a personal GitHub repo and a GitHub release that distributes pre-built binaries (.mcpb / CLI) from a non-official/personal source — a common vector for malware distribution — while the remaining URLs are placeholder API endpoints or known/third-party repos and are not flagged.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 17, 2026, 07:38 AM
Issues
3
Security Audit — snyk — pp-printing-press-oauth2