File appears to expose a hardcoded API secret or token.
- Code
- suspicious.exposed_secret_literal
- Location
- examples/terraform/cbh_stack/main.tf.txt:35
Security audit
Security checks for vulnerabilities and agentic risk
This is a broad Huawei Cloud operations skill with real cloud and MaaS execution paths, but the artifacts disclose those capabilities and mostly gate them behind planning, dry-run, and explicit execution flags.
Install only if you intend to let the agent help manage Huawei Cloud resources or MaaS calls. Use a least-privilege hcloud profile or environment credentials, prefer dry-run/plan modes first, review exact submit tokens and commands before live changes, and avoid running Terraform or billing/account-wide reads in directories or accounts that contain sensitive production state unless you are comfortable with that scope.
SkillSpector could not complete.
Detected: suspicious.exposed_secret_literal