db-seeder
Fail
Audited by Snyk on Feb 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt repeatedly uses and instructs generation of full database connection strings and seeding commands that include plaintext credentials (e.g., --connection "postgresql://user:pass@...") and says the detector will "output connection details and ready-to-use seeding commands," which would require the LLM to handle and potentially emit secret values verbatim.
Audit Metadata