syncfusion-dotnet-word
Fail
Audited by Snyk on Mar 26, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The prompt explicitly tells the skill to "Use license key from SyncfusionLicense.txt at workspace root or env var SYNCFUSION_LICENSE_KEY" and implies embedding that key into generated CSX scripts or C# code, which requires the LLM to read and include the secret value verbatim (high exfiltration risk).
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata