File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:79
Security audit
Security checks across malware telemetry and agentic risk
This is a documentation-only security skill that teaches safer credential handling and does not show hidden execution, exfiltration, or persistence behavior.
This appears safe to install as a credential-handling guide. Users should still follow its main rule: configure real secrets through OpenClaw environment injection or a secrets manager, and do not paste API keys into chat or allow agents to print them in logs.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal