File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- handler.py:12
Security audit
Security checks across malware telemetry and agentic risk
The skill can generate art prompts, but it exposes a SkillPay billing key and is written to charge per use, so it needs review before installation.
Review this skill carefully before installing. The prompt-generation logic is simple, but the exposed SkillPay key and automatic billing path are not appropriate as shipped; use only after the publisher removes the embedded key, declares the payment permissions, and provides clear user approval for charges.
48/48 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal