Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index-sol-safe.js:9
Security audit
Security checks across malware telemetry and agentic risk
The monitor mostly matches its stated purpose, but it embeds a live billing API key and payment-charge logic that users should review carefully before installing.
Review the billing implementation before installing. The monitor code does not show private-key use or automatic trading, but the packaged source contains a hardcoded SkillPay API key and charge logic, and the package appears incomplete for npm-based execution.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal