File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- scripts/global_coverage.js:4
Security audit
Security checks across malware telemetry and agentic risk
This looks like a generic global website-testing tool, but its scripts embed a ScraperAPI key and send proxy/analytics visits to a fixed site instead of the user-provided URL.
Do not use this skill until the hardcoded API key is removed, the documented URL and credential controls are actually implemented, and the tool clearly confirms the target site before making proxy requests. Only run analytics-triggering or multi-country scraping against sites you own or are explicitly authorized to test.
65/65 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal