gemini-auth
Fail
Audited by Snyk on Feb 16, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The prompt includes commands that read or print secrets (echo $GEMINI_API_KEY, cat ~/.gemini/.env, pass show, security add-generic-password -w "...") and examples that embed keys into files/command arguments, so an agent following it may be required to handle or output secret values verbatim.
Audit Metadata