Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/zhitou.mjs:10
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward connector to a disclosed advertising/brand-visibility API and does not show hidden persistence, destructive actions, or unrelated data access.
Install only if you trust ai.wohaoniu.com with the brand and advertising briefs you submit. Configure the API key as an environment variable, avoid pasting it into chat, and remember that hook/script calls may spend credits on your account.
61/61 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access