apiyi-gpt-image-2-all-gen

Fail

Audited by Snyk on Apr 25, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The prompt includes and documents passing API keys directly on the command line (e.g., -k/--api-key "your-api-key-here") and explicit examples of embedding the API key, so an agent could be instructed to request and output a user's secret verbatim in generated commands.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 25, 2026, 02:02 PM
Issues
1