File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:33
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed retail-analysis connector that sends user-provided brand, address, or coordinate queries to a stated DDT API and does not include hidden code or persistence.
Install only if you are comfortable using the DDT service for retail analysis and sharing the brands, addresses, coordinates, or store IDs you ask about with that API provider. Keep the API key in environment variables as instructed and do not paste it into chats or files.
Detected: suspicious.exposed_secret_literal