prophet-market-seeder
Fail
Audited by Snyk on Mar 21, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill instructs the agent to prompt for a 6-digit OTP, extract the Prophet JWT (starting with "eyJ...") and pass it through as PROPHET_SESSION_TOKEN (and shows exporting SEREN_API_KEY/PROPHET_SESSION_TOKEN), which requires the agent to handle and potentially emit secret values verbatim.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata