File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:36
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Maestro integration that uses configured credentials to create/list tasks and send room messages when requested.
Install this only if you trust the configured Maestro connection, because the skill can use that API key to create tasks and post room messages. The artifact tells the agent not to expose credentials and limits behavior to the documented Maestro operations.
Detected: suspicious.exposed_secret_literal