password-protect-pdf
Fail
Audited by Snyk on Mar 7, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill requires the agent to accept an API key and a user password as inputs and include them verbatim in API requests (Authorization: Bearer <API_KEY> header and multipart
userPassfield), which forces secret values into the agent's generated output/requests and creates an exfiltration risk.
Audit Metadata