log-monitor

Fail

Audited by Snyk on Mar 3, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly requires including "actual error messages" and contextual fields (user IDs, request data, SQL queries, etc.) from logs into reports and GitHub issue bodies — log entries can contain API keys, tokens, cookies or plaintext passwords, so the LLM would be instructed to reproduce secret values verbatim.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 3, 2026, 11:54 PM
Security Audit — snyk — log-monitor