simplify
Fail
Audited by Snyk on Mar 21, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The prompt instructs the agent to write "Test credentials: {if auth involved}" into Implementation Notes and to read changed files, which can require copying secrets (API keys/passwords/test credentials) verbatim from files or user input into the agent's output, creating an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata