AGENT LAB: SKILLS

e2e-testing

Fail

Audited by Snyk on Feb 17, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt includes explicit plaintext credentials (e.g., "admin@test.com" and "password123") and shows them embedded in enter_text/tap actions, requiring the agent to output secret values verbatim in generated commands.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). The skill captures and reads app UI (e.g., via screenshot(), inspect_interactive(), get_text()) and explicitly includes workflows that interact with user-generated content such as "create post → like → comment", so the agent can be exposed to arbitrary third-party/public content rendered inside the target app.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 17, 2026, 03:47 PM