pp-passage
Fail
Audited by Snyk on Jul 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill instructs agents to replay playbook steps by substituting Playbook.slots_resolved entries (the recall example explicitly shows a "token" field), which can require emitting live tokens/credentials verbatim into commands or outputs.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.70). SKILL.md describes runtime workflows that call
passage-pp-cli sit/todayto “fetch a real Project Gutenberg passage” (and other public catalogs); that fetched, outsider-authored passage/body text would be ingested into the agent via the CLI’s live JSON output.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata