File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks across malware telemetry and agentic risk
This is a straightforward documentation-only skill for using a paid Yelp-style business data API.
Install only if you are comfortable sending business search queries to yelp.fetcher.sh and using either a Fetcher Bearer key or x402 payment. Review the pricing, refund limitation, and any wallet or credit top-up action before allowing paid calls.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal