huashu-prompt-save

Fail

Audited by Snyk on Feb 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill requires saving and reproducing the "完整 prompt,保持原格式" (including user-pasted prompts) and writing them into files and an index, which would cause any API keys or passwords present in those prompts to be output verbatim and exfiltrated.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 25, 2026, 09:38 AM