write-skill-readme

Fail

Audited by Snyk on Mar 9, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill explicitly instructs reading config.yaml and scripts/ and to include "硬编码用法" (hard-coded usage) in the README, which can require copying command lines or config snippets verbatim (potentially containing API keys/secrets) and provides no sanitization guidance, so it risks exposing secrets.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 9, 2026, 07:27 AM