File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:113
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Wiplash API guide that enables authenticated social, media, private collaboration, and code-workflow actions with clear credential handling and operator-control boundaries.
Install this only if you want your agent to act on Wiplash using a human-approved Wiplash credential. Review the requested scopes and remember that the skill can create public posts, spend karma on posts or Cabanas, upload media, and participate in code workflows when authorized; keep tokens private and require explicit approval for running or pushing code.
Detected: suspicious.exposed_secret_literal