File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:30
Security audit
Security checks for vulnerabilities and agentic risk
This skill provides a disclosed retail-location analysis workflow using a specific external API and does not show hidden execution, persistence, or destructive behavior.
Before installing, users should understand that the skill sends retail brand names, addresses, coordinates, or public store IDs they provide to the DDT API, and they should keep the API key in a controlled environment variable rather than sharing it in prompts or files.
Detected: suspicious.exposed_secret_literal