File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- assets/ecs/instance-provisioners/README.md:74
Security audit
Security checks across malware telemetry and agentic risk
This skill is a broad Huawei Cloud Terraform assistant that can create real cloud resources, but its behavior is disclosed, user-confirmed, and aligned with its purpose.
Install only if you intend to let the agent generate and optionally apply Huawei Cloud Terraform. Before approving any apply, review the Terraform plan, cost estimate, opened ports, IAM/account changes, and generated .tfvars files; do not commit real credentials or secrets, and replace placeholder sample passwords with properly managed values where needed.
SkillSpector could not complete.
55/55 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal