social-media-scheduler

Fail

Audited by Snyk on Mar 20, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill explicitly asks for the user's affiliate link (affiliate_url) and requires embedding that link verbatim into post copy and the output schema, forcing the LLM to handle and output a user-provided secret/identifier directly (exfiltration risk).

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Mar 20, 2026, 07:32 AM
Issues
1