File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- .env.example:3
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s presentation-generation purpose is coherent, but its installer and optional Codex backend create review-worthy credential and broad-agent-execution risks.
Detected: suspicious.exposed_secret_literal