File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- README.md:30
Security audit
Security checks for vulnerabilities and agentic risk
SkillBoss appears to be a coherent paid AI-tool gateway, but it gives the agent broad wallet-backed authority to call many external tools, so users should review scope and budget controls carefully.
Install this only if you intentionally want your agent to use SkillBoss credits for external AI tools. Start with a low-balance or scoped key, set strict per-call and daily budgets, avoid enabling the generic dispatcher unless necessary, require review for email or purchase-like actions, and verify the npm package source before installing.
Detected: suspicious.exposed_secret_literal