czsc-thinking

Fail

Audited by Snyk on Mar 4, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The quickstart shows passing a Tushare token via a --token command-line argument (e.g., python ... --token YOUR_TUSHARE_TOKEN), which instructs the agent/user to embed a secret verbatim in commands—an exfiltration risk.
Audit Metadata
Risk Level
HIGH
Analyzed
Mar 4, 2026, 05:21 PM