polyhub_account
Fail
Audited by Snyk on Mar 23, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly instructs the user to "Send me the generated key" and includes curl examples that embed the API key into requests (even if via an env var), meaning the LLM may receive and be asked to use or reproduce the secret in generated commands—creating an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata