File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:42
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward guide for using a paid App Store data API and does not contain hidden execution, persistence, or unrelated data access.
Before installing, understand that queries and app identifiers are sent to fetcher.sh and paid calls may use prepaid credits or x402 payment; only configure an API key or MCP header if you trust that service for this use.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal