security-reviewer

Fail

Audited by Snyk on Feb 24, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt instructs the reviewer to "show the vulnerable code" and to check for hardcoded credentials/tokens, which will likely cause the model to reproduce secret values found in submitted code (verbatim), creating an exfiltration risk even though it doesn't explicitly ask for secrets.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 24, 2026, 06:34 AM