super-save

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill formats arbitrary conversation content into a quoted shell command argument and instructs the agent to emit that command verbatim, so any secrets present in the saved content (API keys, passwords, tokens, cookies) would be included in the LLM's output and exfiltrated.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 04:02 AM