Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/dexscreener-cli.mjs:3
Security audit
Security checks across malware telemetry and agentic risk
This is a read-only DexScreener lookup skill that sends user-provided market queries to a public API and shows no wallet, trading, persistence, or credential behavior.
Reasonable to install for read-only DexScreener market lookups. Do not enter wallet seed phrases, private keys, or other secrets as search text, and only set DEXSCREENER_BASE_URL to an endpoint you trust because it will receive your lookup queries.
66/66 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.secret_argv_exposure