File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:41
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward guide for using a paid Google search-results API and does not contain hidden execution, persistence, or unrelated data access.
Review the pricing and payment method before enabling it. If you use the MCP configuration, protect the Bearer key and monitor calls because paid search and top-up actions are part of the documented service.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal