workspaces

Fail

Audited by Snyk on Apr 12, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt requires including a Domo developer token in request headers and provides a Python example that sets TOKEN to a literal token string (encouraging embedding secrets in code), so an agent could be asked to emit the secret verbatim even though some curl examples use env vars.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 12, 2026, 05:26 PM
Issues
1