Source: RepoLens Security-Audit 2026-08-16 (findings security/authorization/001–005+007, security/secrets/002+004–006, adversarial-verified ✅)
Skill docs teach insecure patterns that get copied into real code:
001 Telegram wildcard * allow-everyone example
002/006 WS/REST patches re-enabling ?token= in query strings
003 _TokenPasswordProvider static credential pattern
004 PUBLIC_API_PATHS documented as auth-bypass knob
007 gateway-adapter-development documents allow_all_env as first-class option
secrets/002 .gitignore misses credential filename patterns (partially fixed in 182b3fd)
secrets/004 Harbor default password Harbor12345 as CLI fallback
secrets/005 Telegram bot token passed as curl argv (visible in process list)
secrets/006 api-discovery.sh echoes token prefix to stdout
Suggested fix: rewrite doc examples to the secure variants (env vars, headers, fail-closed), add a doc-lint grep to CI.
Source: RepoLens Security-Audit 2026-08-16 (findings
security/authorization/001–005+007,security/secrets/002+004–006, adversarial-verified ✅)Skill docs teach insecure patterns that get copied into real code:
001Telegram wildcard*allow-everyone example002/006WS/REST patches re-enabling?token=in query strings003_TokenPasswordProviderstatic credential pattern004PUBLIC_API_PATHSdocumented as auth-bypass knob007gateway-adapter-developmentdocumentsallow_all_envas first-class optionsecrets/002.gitignore misses credential filename patterns (partially fixed in 182b3fd)secrets/004Harbor default passwordHarbor12345as CLI fallbacksecrets/005Telegram bot token passed as curl argv (visible in process list)secrets/006api-discovery.sh echoes token prefix to stdoutSuggested fix: rewrite doc examples to the secure variants (env vars, headers, fail-closed), add a doc-lint grep to CI.