← back to saas-scaffolder

SkillSpector · saas-scaffolder

independent scanner by NVIDIA · skill by neekware · how it works ↗

PASSmax severity: LOWrisk score: 15

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.; Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the atta…

scanned 2026-08-23

Findings (11)

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/auth-billing-guide.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/auth-billing-guide.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/auth-billing-guide.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/auth-billing-guide.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/auth-billing-guide.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/saas-architecture-patterns.md

HIGHPrivilege Escalationconfidence: 0.21

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

references/saas-architecture-patterns.md

HIGHPrivilege Escalationconfidence: 0.6

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

scripts/project_bootstrapper.py.md

HIGHPrivilege Escalationconfidence: 0.6

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

scripts/project_bootstrapper.py.md

HIGHPrivilege Escalationconfidence: 0.6

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

scripts/project_bootstrapper.py.md

MEDIUMTool Misuseconfidence: 0.6

Tool defaults are unsafe or overly permissive (e.g. disabled TLS verification, no authentication, world-writable permissions). Unsafe defaults widen the attack surface.

scripts/project_bootstrapper.py.md

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASSthis skill

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete