datalens-yc-rls-resolve
>-
Install this skill
or
50/100
Security score
The datalens-yc-rls-resolve skill was audited on Sep 14, 2026 and we found 2 security issues across 1 threat category, including 2 critical. Review the findings below before installing.
Categories Tested
Security Issues
critical line 120
Instruction to extract credentials
SourceSKILL.md
| 118 | |
| 119 | Prefer the wrapper so a live token is never exposed. **Backstop — never run these yourself:** |
| 120 | `yc iam create-token` without redirecting output, or `yc config list` / `yc config get token` — |
| 121 | they print the OAuth token / SA key into the transcript. Never print, echo, log, or store any |
| 122 | token or key. (`yc config profile list`, which shows only profile names, is fine.) |
critical line 185
Instruction to extract credentials
SourceSKILL.md
| 183 | ## Common mistakes |
| 184 | |
| 185 | - **Leaking the token.** Never run `yc config list` / `yc config get token` or an unredirected |
| 186 | `yc iam create-token`. Check auth only via `python3 scripts/rls_tool.py auth-check`. |
| 187 | - **Handing work to the user.** Drive `yc init` and run the resolver yourself; don't tell |
Scanned on Sep 14, 2026
View Security DashboardGitHub Stars 10
Rate this skill
Categorydevelopment
UpdatedSeptember 28, 2026
datalens-tech/datalens-skills