env-config-validator
Fail
Audited by Snyk on Feb 16, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The skill includes many explicit secret-like examples and sample .env edits that embed credentials verbatim (DB URLs, JWTs, sk_live/sk_test keys), which encourages or requires the agent to display or reproduce secret values in outputs even though the validation script could be run without the model seeing secrets—so there's a substantial exfiltration risk.
Audit Metadata