spanora-setup

Fail

Audited by Snyk on Feb 19, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill explicitly asks the user for their Spanora API key and instructs storing/using it in .env (and to read it from .env if present), which requires the agent/LLM to handle and output the secret value verbatim.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 19, 2026, 01:30 AM