third-party-cookies

Fail

Audited by Snyk on Aug 11, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly tells the agent to "identify Set-Cookie headers" and to "Flag exact responses, cookies..." which would require outputting cookie header values (potentially session/auth tokens) verbatim, creating an exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 11, 2026, 12:31 AM
Issues
1
Security Audit — snyk — third-party-cookies