codex

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly embeds repo diffs and full plan file contents into prompts (which can contain API keys, tokens, or passwords) and then mandates presenting Codex's output verbatim, forcing the model to handle and potentially echo secret values from those inputs.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 03:58 AM
Issues
1
Security Audit — snyk — codex