Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/breakdown.mjs:20
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward Plausible Analytics helper that uses your Plausible API key only to read analytics from Plausible.
Install only in an environment where you are comfortable exposing PLAUSIBLE_API_KEY to this skill. Prefer a limited or read-only Plausible key if available, confirm the site ID before running commands, and treat returned analytics such as referrers, pages, countries, and traffic counts as potentially sensitive.
65/65 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access