reflect

Fail

Audited by Snyk on Apr 26, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt requires reading raw command audit logs and producing data-driven listings and sequences (e.g., most-used commands and command invocations) but gives no instruction to redact sensitive fields, so it could force the LLM to reproduce embedded API keys/tokens/credentials verbatim from those logs.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 26, 2026, 05:44 PM
Issues
1