File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- scripts/init-mcporter-oauth.sh:77
Security audit
Security checks across malware telemetry and agentic risk
This is a disclosed WordPress.com MCP connector that can manage site content using the user's OAuth grant, with no artifact evidence of hidden or malicious behavior.
Install this only for WordPress.com accounts and sites where you are comfortable letting an agent act through the connected OAuth grant. Use the least-privileged account available, review write/publish/delete/moderation actions before they run, and revoke the OAuth grant in WordPress.com when you no longer need the skill.
65/65 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal