File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:40
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed Google Play data lookup integration that may spend credits or x402 payments when the user chooses to call the external API.
Before installing, confirm you are comfortable using fetcher.sh as a paid third-party data provider. Keep the bearer key private, understand that calls are billed at the documented rate or via x402 payment, and note the artifact says upstream failures are not refunded after settlement.
60/60 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal