Skills boost Audit History
📦

Audit History

boost - 1 audit

Sep 28, 2026, 04:21 PM

All 104 static findings are false positives involving Markdown formatting, intended service URLs, credential placeholders, or provider setup documentation. One semantic finding concerns authentication secrets supplied through CLI arguments, which can expose them locally. No evidence found of prompt injection, malicious execution, or unauthorized exfiltration in the reviewed files.

3
Files scanned
323
Lines analyzed
4
Review items
0
False positives ignored

Confirmed security concerns (1)

Medium
Provider Credentials Exposed Through CLI Arguments
The guide recommends 'provider add --header k:v' for a persistent provider credential. Substituting secrets into command arguments can expose them through shell history and process listings.
Line 220 explicitly recommends CLI header arguments for credentials, while the interactive-input safeguard on line 174 covers only provider connect. Actual exposure depends on execution and host controls.
Audited by: codex