File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:272
Security audit
Security checks across malware telemetry and agentic risk
AgentYield is a disclosed observability skill that sends limited, redacted usage telemetry to its own service for cost analysis.
Install only if you want AgentYield to receive redacted OpenClaw usage telemetry. Use a test key for evaluation, keep the API key in the environment, and review AgentYield's retention and deletion controls before using a live key.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal