workspaces
Fail
Audited by Snyk on Apr 12, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt requires including a Domo developer token in request headers and provides a Python example that sets TOKEN to a literal token string (encouraging embedding secrets in code), so an agent could be asked to emit the secret verbatim even though some curl examples use env vars.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata