triage-validation

Fail

Audited by Snyk on Aug 27, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill forces "copy-paste ready" HTTP requests (headers/body) and says "If you CANNOT write step 2 as a real HTTP request → KILL IT", which effectively requires embedding live auth headers/cookies/tokens verbatim in PoCs — a direct secret-exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 27, 2026, 05:32 AM
Issues
1
Security Audit — snyk — triage-validation