a6-plugin-ai-prompt-decorator

Fail

Audited by Snyk on Jul 23, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill document includes literal bearer tokens (e.g., "Bearer sk-your-key" / "Bearer sk-key") in multiple example configs and curl/json snippets, which encourages embedding API secrets in configs and could require the LLM to emit those secret values verbatim when generating or reproducing those examples.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 23, 2026, 12:22 PM
Issues
1
Security Audit — snyk — a6-plugin-ai-prompt-decorator