critical
suspicious.exposed_secret_literal
- Location
- dist/dingtalk/client.js:71
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
clientSecret: [REDACTED],
AdvisoryAudited by Static analysis on May 10, 2026.
Detected: suspicious.exposed_secret_literal
clientSecret: [REDACTED],
OPENCODE_SERVER_PASSWORD: [REDACTED],