depot-container-builds

Fail

Audited by Snyk on Jun 24, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt includes examples that embed API tokens and depot tokens directly in CLI commands/flags (e.g., --token and docker login -p ), which encourages the LLM to emit secrets verbatim in generated commands and thus presents an exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 24, 2026, 06:17 PM
Issues
1
Security Audit — snyk — depot-container-builds