gemini

Fail

Audited by Snyk on Aug 15, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill explicitly captures git diffs and other context (including DIFF=$(git diff ...)) and injects ${CONTEXT} verbatim into gemini CLI prompts, which will cause the LLM/agent to see and potentially re-emit any secrets present in the repo or context (API keys, tokens, passwords) — an exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 15, 2026, 03:14 PM
Issues
1
Security Audit — snyk — gemini