feature-council

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The skill forces forwarding the user's raw prompt verbatim to multiple solver agents and directs modification/creation of config/code (e.g., adding config entries), so any API keys or passwords present in the prompt or discovered in the repo could be propagated and emitted verbatim, creating a high exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 01:16 AM