critical
suspicious.exposed_secret_literal
- Location
- dist/index.mjs:9
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
const DEFAULT_CLIENT_SECRET = "[REDACTED]";
AdvisoryAudited by Static analysis on May 14, 2026.
Detected: suspicious.exposed_secret_literal, suspicious.potential_exfiltration
const DEFAULT_CLIENT_SECRET = "[REDACTED]";
const raw = await readFile(tokenFile, "utf-8");