codex-app-remote-exec
Fail
Audited by Snyk on Jul 2, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). This prompt instructs the agent to locate an opaque remote-control host id from logs and embed that id verbatim into command-line invocations (e.g., --host-id 'remote-control:env_<opaque_id>'), which requires the LLM to handle and emit a sensitive identifier from user/device logs and therefore poses an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata