competition-jwt-claim-confusion

Fail

Audited by Snyk on Jun 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). 该技能要求记录并输出“原始 header、claims、JWKS/本地密钥路径”和“可重放的最小令牌到接受序列”,实质上会让模型包含或复述完整的 JWT/密钥或类似敏感凭证值,存在高风险的凭证泄露。

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 20, 2026, 03:16 AM
Issues
1
Security Audit — snyk — competition-jwt-claim-confusion