ravi-passwords
Fail
Audited by Snyk on Apr 10, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill explicitly returns and expects plaintext passwords (JSON responses include "password", examples show extracting and using the password, and commands accept --password arguments), which requires the LLM to read and potentially output secret values verbatim.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata