File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:33
Security audit
Security checks for vulnerabilities and agentic risk
This is a focused API-guidance skill for automotive aftermarket channel analysis, with expected network/API-key use and no hidden execution or persistence.
Install this only if you are comfortable setting a local DDT API key and sending queried brands, addresses, or coordinates to the DDT service. Do not paste the API key into chats, logs, or files; the skill itself also instructs agents not to expose it.
Detected: suspicious.exposed_secret_literal