smart-data-analysis
Fail
Audited by Snyk on Apr 29, 2026
Risk Level: HIGH
Full Analysis
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). I scanned the full skill prompt for literal high-entropy values. The only candidate that looks like a real, usable credential is the alphanumeric ID "d71o5e1e8q1nr9l7mb80" in the typical call:
"/smart-data-analysis 用 d71o5e1e8q1nr9l7mb80 查询快讯传媒有限公司住址"
This value is not a generic placeholder (e.g., YOUR_API_KEY) nor an obvious low-entropy setup password. It is a random-looking, medium/long alphanumeric string that could be a kn_id or service identifier used to access a knowledge network, so it may be a usable secret/credential. All other strings in the document are names, commands, filenames, or clearly documentation placeholders and were ignored per the rules.
Issues (1)
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata