File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:385
Security audit
Security checks across malware telemetry and agentic risk
This is a documentation-style Bolta skills registry that clearly discloses its credential needs, network endpoints, and safety expectations, with no executable code or hidden behavior found.
Install only if you trust Bolta and the listed domains. Use a least-privilege Bolta key scoped to the intended workspace, avoid editor/admin or team-management authority unless needed, and verify the GitHub repository before following the broader skill-pack installation steps.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal