fable-safe-prompt

Fail

Audited by Snyk on Aug 10, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly requires returning the user's prompt "in full, verbatim" (with minimal edits) and placing it inside a pbcopy shell block, so any API keys/passwords/cookies present in the user's prompt would be echoed verbatim by the model and copied to the clipboard, creating a high exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 10, 2026, 07:31 PM
Issues
1
Security Audit — snyk — fable-safe-prompt