critical
suspicious.exposed_secret_literal
- Location
- dist/src/config.js:36
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
const apiKey = [REDACTED](ws.apiKey) ?? readEnv(ENV_API_KEY);
AdvisoryAudited by Static analysis on May 18, 2026.
Detected: suspicious.exposed_secret_literal
const apiKey = [REDACTED](ws.apiKey) ?? readEnv(ENV_API_KEY);