workflow-runner

Fail

Audited by Snyk on Jun 21, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). 该技能会把任意用户提供的输入(包括必填项)原样替换进 task 模板并输出/写入文件或子代理提示,意味着如果输入是 API Key/密码/Token 等秘密,LLM 会在生成的命令、代码或文件中直接暴露这些秘密。

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 21, 2026, 02:13 PM
Issues
1
Security Audit — snyk — workflow-runner