unified-execute-with-file

Fail

Audited by Snyk on Mar 8, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). This skill executes and logs verification commands and task details verbatim (e.g., storing ${verification} → PASS in verificationOutput and appending it to execution-events.md / task _execution), so any secrets embedded in task commands (like curl Authorization headers or tokens) would be written into outputs and thus exfiltrated.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 8, 2026, 03:43 PM