source-command-gsd-join-discord
Fail
Audited by Snyk on May 12, 2026
Risk Level: HIGH
Full Analysis
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). The document contains a full, non-placeholder Discord invite URL (https://discord.gg/mYgfVNfA2r). This is a direct, usable access token-like value (random-looking suffix) that grants entry to a service/community and is not a generic placeholder or example. It meets the definition of a high-entropy literal that provides access, so I flag it. If this invite is intentionally public documentation, it may be acceptable, but it still qualifies as a secret under the provided definition.
Issues (1)
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata