File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- memory-template.md:67
Security audit
Security checks for vulnerabilities and agentic risk
This is a defensive cybersecurity guidance skill that stores scoped local notes, with clear authorization gates and no executable installer or hidden network behavior found.
Before installing, understand that the skill is designed to keep durable local security notes under the declared Clawic data folders. That can include incident summaries, findings, contacts, assets, vendor information, and due dates, but it explicitly says not to store credentials, raw evidence, or personal records there.
Detected: suspicious.exposed_secret_literal