coolify

Fail

Audited by Snyk on Mar 1, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt contains many examples that embed secrets verbatim into commands or configs (e.g., export COOLIFY_TOKEN="your-token-here", --private-key "$(cat ~/.ssh/id_rsa)", --postgres-password secret, and inline API keys), meaning the agent would need to include secret values directly in its outputs.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 1, 2026, 05:14 AM