password-protect-pdf

Fail

Audited by Snyk on Mar 7, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill requires the agent to accept an API key and a user password as inputs and include them verbatim in API requests (Authorization: Bearer <API_KEY> header and multipart userPass field), which forces secret values into the agent's generated output/requests and creates an exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 7, 2026, 12:35 PM