competition-cloud-metadata-path

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). 该技能明确要求收集并保存“已签发的令牌或凭证”并复现可重放的元数据到特权链,这会使模型需要在输出中包含机密令牌/凭证的原文,存在敏感信息外泄风险。

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). 该文档明确提供了利用云/容器元数据端点、SSRF 与工作负载身份获取并滥用临时凭证以实现凭证窃取、数据外泄和权限提升的分步指导,属于明确的恶意滥用模式。

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jun 20, 2026, 03:16 AM
Issues
2
Security Audit — snyk — competition-cloud-metadata-path