update-role

Fail

Audited by Snyk on Apr 1, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill reads role files and must show unified diffs verbatim (including vars/defaults), so any secrets stored in those files would be exposed in the agent's output — the prompt's only mitigation is adding no_log to new tasks, not masking or avoiding existing secret values.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 1, 2026, 03:36 AM
Issues
1