File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:33
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed retail site-selection helper that uses a named external API and does not install code, persist, or request hidden access.
Before installing, users should understand that relevant brand, address, and coordinate queries may be sent to the publisher's API, and they should provide a DDT_API_KEY only in a controlled environment. The skill appears scoped to read-only analysis and includes clear limits around unsupported data and credential handling.
Detected: suspicious.exposed_secret_literal