File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward guide for using a paid Yelp-data API through fetcher.sh, with the payment and credential requirements disclosed.
Review fetcher.sh pricing and payment mechanics before use, especially the bearer-key and x402 options, because calls are paid and the skill says refunds are not provided on upstream failures. Install only if you are comfortable sending search queries and business/review requests to this third-party service.
Detected: suspicious.exposed_secret_literal