flow-hybrid-search

Fail

Audited by Snyk on Mar 4, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt instructs running commands that pass an API key as a command-line --token "$TIANGONG_LCA_APIKEY" (i.e., embedding the secret in generated shell commands), which requires the agent to handle or output the secret verbatim and is therefore high-risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 4, 2026, 01:07 AM