Exposed secret literal
Critical
- Finding
- File appears to expose a hardcoded API secret or token.
Security checks across static analysis, malware telemetry, and agentic risk
No artifact-backed suspicious behavior could be confirmed because the workspace files could not be read in this sandbox run.
Treat this as an incomplete review, not a clean security assessment; install only after metadata.json and the artifact directory are successfully inspected.
SkillSpector findings are pending for this release.
VirusTotal engine telemetry is currently stale for this artifact.