llm-ai-security

Fail

Audited by Snyk on May 9, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly includes curl examples that interpolate and send a bearer token/session cookie in headers and contains payloads that instruct the model to "output the admin password" or exfiltrate system prompt data, which require secrets to appear verbatim in requests/responses.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 1.00). This skill's workflow explicitly instructs sending and processing untrusted, user-controlled content (e.g., "document uploads, pasted text, web page summaries, database records, emails, or calendar events" in Step 4, plus web_search/tool-invocation tests in Steps 6 and 9), so the agent is expected to ingest and act on arbitrary third‑party content that could carry indirect prompt injections.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
May 9, 2026, 02:07 AM
Issues
2
Security Audit — snyk — llm-ai-security