File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:30
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed, scoped API-integration guide for automotive aftermarket store-network analysis and does not include hidden execution or persistence.
Before installing, confirm you trust the DDT service endpoint and keep DDT_API_KEY in your local environment only. Expect the skill to send brand names, coordinates, store IDs, or pasted address text to that API for automotive aftermarket analysis.
Detected: suspicious.exposed_secret_literal