todo-task-run
Fail
Audited by Snyk on Feb 16, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill requires reading and embedding file contents and prior task results (summaries, files_modified, key_findings) verbatim into prompts passed to subagents, which can cause any secrets found in those files (API keys, tokens, or passwords) to be propagated and output by the LLM.
Audit Metadata