Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/geckoterminal-cli.mjs:8
Security audit
Security checks across malware telemetry and agentic risk
This skill is a read-only GeckoTerminal market-data helper that does not access wallets, credentials, files, or trading functions.
Install this if you are comfortable sending requested network, token, pool, and search-query values to GeckoTerminal's public API. It does not need API keys or wallet access, but market data should be treated as informational rather than trading advice.
66/66 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.secret_argv_exposure