add-whatsapp-cloud

Fail

Audited by Snyk on Aug 18, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill's nc:prompt directives ask the user to paste secrets (access token, app secret, verify token) and the nc:env-set consumer interpolates those values ({{access_token}}, etc.) into an env file, which requires the agent to include the secret values verbatim in its generated output/commands.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 18, 2026, 03:10 AM
Issues
1
Security Audit — snyk — add-whatsapp-cloud