NYC

act-workflow-syntax

Fail

Audited by Snyk on Feb 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt includes examples that embed secrets verbatim (e.g., a .secrets file with GITHUB_TOKEN=ghp_your_token_here and CLI usage act -s GITHUB_TOKEN=ghp_token -s API_KEY=key), which instructs outputting or copying secret values directly and therefore creates an exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 10:11 AM