fpf-core

Fail

Audited by Snyk on Mar 1, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt requires the agent to write a session_id value verbatim into a sentinel file (session_id=<CLAUDE_SESSION_ID>), which forces inclusion of a secret-like token in generated output and thus poses an exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 1, 2026, 07:14 PM