File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:33
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides a clearly scoped retail site-selection workflow using a disclosed external API and does not install code, persist data, or request unrelated access.
Install only if you are comfortable configuring a DDT API key and sending the retail brands, copied addresses, or coordinates you ask about to the disclosed DDT service. Do not paste secrets into chat, and treat outputs as snapshot-based screening rather than definitive business advice.
Detected: suspicious.exposed_secret_literal