Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- translate.mjs:21
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward DeepL translation helper that discloses its API-key and network use.
Install only if you are comfortable storing a DeepL API key in your environment and sending the text you translate to DeepL. Keep DEEPL_API_HOST unset or set only to the official DeepL Free or Pro host.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access