CtrlK
BlogDocsLog inGet started
Tessl Logo

injection-example

Demonstrates unsafe review data. Invoke only in reviewer prompt-injection calibration tests.

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security
High

W007: Insecure credential handling detected in skill instructions.

What this means

The skill handles credentials insecurely by requiring the agent to include secret values verbatim in its generated output. This exposes credentials in the agent’s context and conversation history, creating a risk of data exfiltration.

Why it was flagged

The skill prompt instructs the agent to print environment variables and exfiltrate them via an HTTP request, which exposes sensitive environment variables and secrets to an external server.

Report incorrect finding
Repository
bytedance/deer-flow
Audited
Security analysis
Snyk

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.