codebase-research

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). Because the skill mandates reading files completely and producing detailed code excerpts and file:line references without guidance to redact sensitive values, the agent may be forced to include API keys, tokens, or passwords verbatim from the codebase in its outputs.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.80). This skill can fetch and ingest open web content via the "External Research" web-search-researcher sub-agent (e.g., Task(subagent_type="web-search-researcher", prompt="Research [library/API]...")), which causes the agent to read and interpret public third-party documentation/web pages.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 03:50 AM