credits-inventory
Fail
Audited by Snyk on Feb 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs the agent to read private emails and extract and include claim URLs and promo codes (and other secret-like tokens/credit values) verbatim in generated instructions and inventory, which requires handling secrets in output and creates an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The SKILL.md explicitly instructs the agent to search and read the user's Gmail via gscli (gscli gmail search / gscli gmail read) and to follow/fetch external claim URLs and public perks pages (e.g., brex.com/perks, aws.amazon.com/activate) — i.e., it ingests untrusted third‑party emails and web pages as part of its workflow, which could contain instructions that materially influence agent actions.
Audit Metadata