compare-to-notte-costs
Fail
Audited by Snyk on Jul 30, 2026
Risk Level: HIGH
Full Analysis
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I scanned the files for high-entropy literal values that could grant access. The Slack shared-invite URL token (zt-39a8n6hr9-d_BG7RNfytimSpVo5H03mA) in SKILL.md is a high-entropy string that likely grants access to a Slack workspace and is therefore a usable credential. Other strings (CLI commands, placeholder references like URLs, variable/prompt names, simple example text) are low-entropy, documentation placeholders, or usage examples and were ignored per the rules.
Issues (1)
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata