software-evaluation
Fail
Audited by Snyk on Feb 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The prompt explicitly instructs scanning config/secrets and gives examples that reproduce hardcoded credential literals (e.g.,
|| "password123"), and it requires citing file:line evidence and P0 blockers which makes it likely the LLM will need to surface exact secret values verbatim to justify findings—creating an exfiltration risk.
Audit Metadata