Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:23
- Evidence
apiKey: process.env.NOTFAIR_API_KEY || (typeof cfg.apiKey === "string" ? cfg.apiKey : undefined),
Security audit
Security checks for vulnerabilities and agentic risk
The plugin is a disclosed NotFair integration for ads and analytics, with expected credential storage and user-approved write operations.
Install only for workspaces where NotFair should access connected ad and analytics accounts. Review any proposed write carefully because approved operations can affect campaign state, bids, budgets, ads, keywords, or analytics configuration; use logout to clear stored credentials when no longer needed.
Detected: suspicious.env_credential_access
apiKey: process.env.NOTFAIR_API_KEY || (typeof cfg.apiKey === "string" ? cfg.apiKey : undefined),