Back to skill
Skillv0.2.1

Static analysis security

hum · Deterministic local checks for risky code patterns and metadata mismatches.

Scanner verdict

SuspiciousApr 30, 2026, 5:34 AM
Summary
Detected: suspicious.env_credential_access, suspicious.potential_exfiltration
Reason codes
suspicious.env_credential_accesssuspicious.potential_exfiltration
Engine
v2.4.5

Evidence

criticalscripts/lib/vendor/bird-search/lib/runtime-query-ids.js:50
Environment variable access combined with network send.
suspicious.env_credential_access
criticalscripts/lib/vendor/bird-search/lib/twitter-client-base.js:38
Environment variable access combined with network send.
suspicious.env_credential_access
warnscripts/lib/vendor/bird-search/lib/runtime-query-ids.js:1
File read combined with network send (possible exfiltration).
suspicious.potential_exfiltration