env-config-validator

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill includes many explicit secret-like examples and sample .env edits that embed credentials verbatim (DB URLs, JWTs, sk_live/sk_test keys), which encourages or requires the agent to display or reproduce secret values in outputs even though the validation script could be run without the model seeing secrets—so there's a substantial exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 01:06 AM