critical
suspicious.exposed_secret_literal
- Location
- skills/wechat-mp-illustrate/scripts/illustrate.py:69
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
client = client_class(api_key=[REDACTED], model=args.model)
AdvisoryAudited by Static analysis on May 10, 2026.
Detected: suspicious.exposed_secret_literal, suspicious.potential_exfiltration
client = client_class(api_key=[REDACTED], model=args.model)
encoded = base64.b64encode(path.read_bytes()).decode("ascii")