competition-cloud-metadata-path
Fail
Audited by Snyk on Jun 20, 2026
Risk Level: CRITICAL
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). 该技能明确要求收集并保存“已签发的令牌或凭证”并复现可重放的元数据到特权链,这会使模型需要在输出中包含机密令牌/凭证的原文,存在敏感信息外泄风险。
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). 该文档明确提供了利用云/容器元数据端点、SSRF 与工作负载身份获取并滥用临时凭证以实现凭证窃取、数据外泄和权限提升的分步指导,属于明确的恶意滥用模式。
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
E006
CRITICALMalicious code pattern detected in skill scripts.
Audit Metadata