competition-bundle-sourcemap-recovery

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). 该技能明确要求记录并保留“endpoint strings”和“config keys”及确切执行的 bundle/module 内容,要求模型处理并输出这些值(可能包含 API 密钥或密码),存在将敏感凭据逐字复述并外泄的高风险。

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). At runtime the skill instructs the agent to “Start from the served artifact set” (entry HTML, build manifest, bootstrap bundle, chunk map, and source maps) and to load those served assets/URLs for analysis, which commonly includes outsider-authored web content or downloaded artifacts not authored by the operating user.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 03:16 AM
Issues
2
Security Audit — snyk — competition-bundle-sourcemap-recovery