english-prompt-optimizer

Fail

Audited by Snyk on Feb 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly translates and echoes the user's prompt (in a code block) and then proceeds to execute it, so any API keys, tokens, or passwords included in the user's original non-English input would be reproduced verbatim and possibly used in generated outputs—creating a direct exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 25, 2026, 02:34 PM