local-eks-development

Fail

Audited by Snyk on Feb 27, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt embeds literal secrets and passwords in configs and scripts (e.g., KEYCLOAK_ADMIN_PASSWORD=admin, POSTGRES_PASSWORD=keycloak, clientSecret/local-dev-secret, aws --secret-string "local-dev-secret"), and includes commands that pass these values verbatim, so an agent following it would need to handle/output secret values directly.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).


MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
HIGH
Analyzed
Feb 27, 2026, 07:28 PM