Credential Access
High
- Category
- Privilege Escalation
- Content
.nyc_output/ # Misc .env .env.local
- Confidence
- 60% confidence
- Finding
- Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
Security audit
Security checks for vulnerabilities and agentic risk
This is a Markdown prompt-template skill with broad but disclosed prompt-generation behavior and no artifact-backed evidence of credential theft, exfiltration, persistence, or code execution.
Reasonable to install if you want a prompt-template library. Treat generated prompts and downstream AI-generated code as drafts: review security-sensitive outputs such as authentication, payments, analytics, ads, and token handling before using them in production. The security claims in SECURITY.md are stronger than the visible Markdown-only implementation proves, so do not rely on them as a guarantee.
.nyc_output/ # Misc .env .env.local
# Misc .env .env.local
## 🤝 Contributors ### Code Contributors <!-- This will be automatically updated by GitHub Actions --> None yet - be the first! ### Template Contributors
### Data Privacy - ❌ **No data collection**: This skill doesn't send data to external servers - ❌ **No tracking**: We don't track how you use generated prompts - ✅ **Local processing**: All prompt generation happens locally - ✅ **Your prompts are yours**: Generated prompts are not stored or shared
- Include malicious code - Add obfuscated content - Submit untested templates - Bypass security reviews ``` ## Known Security Issues
- At least 1 uppercase letter - At least 1 number - At least 1 special character - Token Storage: Use flutter_secure_storage for iOS Keychain and Android Keystore - Session Timeout: 30 days, configurable - Rate Limiting: Max 5 login attempts per 15 minutes
## 💡 Pro Tips 1. **Iterate**: Start with basic version, add complexity as needed 2. **Test Early**: Run generated code immediately to validate 3. **Customize**: Adjust generated code to match your style 4. **Save**: Keep successful prompts for future use 5. **Share**: Contribute successful prompts back to community
### Immediate Actions 1. **Create GitHub Repository** ```bash # Go to https://github.com/new # Name: skill-prompt-generator
**Input:** ``` Create a prompt for user authentication in my Flutter app ``` **Output:**
Attempted: - Reinstalled pods - Cleaned build folder - Checked permissions in Info.plist Provide: 1. Root cause analysis
### Data Privacy - ❌ **No data collection**: This skill doesn't send data to external servers - ❌ **No tracking**: We don't track how you use generated prompts - ✅ **Local processing**: All prompt generation happens locally - ✅ **Your prompts are yours**: Generated prompts are not stored or shared
3. الوصف: AI Prompt Generator skill for OpenClaw with Flutter templates 4. نوعه: Public 5. لا تضف README (لدينا واحد) 6. اضغط "Create repository" ``` ### 2️⃣ رفع الملفات
3. lلوصف: AI Prompt Generator skill for OpenClaw with Flutter templates 4. نوعo: Public 5. لl تضف README (لدينl وlحد) 6. lضغط "Create repository" ``` ### 2️⃣ رفع lلملفlت
No suspicious patterns detected.