File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:27
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent retail site-selection assistant that uses a disclosed external API and does not show hidden installation, persistence, or destructive behavior.
Install only if you intend to use the DDT retail API. Treat brand queries, candidate coordinates, and store IDs as data sent to that provider, and keep DDT_API_KEY in a controlled environment rather than chat, logs, or source control.
Detected: suspicious.exposed_secret_literal