Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/metra.mjs:37
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed Metra transit lookup tool that uses a Metra API key and local GTFS cache in ways that match its purpose.
Install only if you are comfortable providing a dedicated Metra API key, running npm install for the protobuf dependency, and allowing a public schedule cache under ~/.metra/gtfs. Keep unrelated secrets out of the skill-local .env file.
56/56 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access