dingtalk-workflow-morning-brief
Fail
Audited by Snyk on Apr 14, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill's workflows and example commands require embedding robot-code and openConversationId (bot credentials/IDs) directly into CLI calls (e.g., --robot-code "bot_code"), which forces secrets/IDs to be placed verbatim in generated commands—an exfiltration risk.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata