File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:40
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed paid API guide for fetching Google Play app data through fetcher.sh, with no bundled executable code or hidden behavior found.
Before installing, confirm you trust fetcher.sh with the API key or x402 payment flow you choose, and be aware that paid calls are disclosed as non-refundable if upstream failures occur.
Detected: suspicious.exposed_secret_literal