Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/github-search.mjs:74
Security audit
Security checks across malware telemetry and agentic risk
This skill searches GitHub for starter repositories and its optional GitHub token use is disclosed and limited to GitHub API calls.
Install this if you want Codex to look for public GitHub starter repositories before building from scratch. If you set GITHUB_TOKEN, use a minimally scoped token or leave it unset when unauthenticated public search is enough.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access