File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:72
Security audit
Security checks across malware telemetry and agentic risk
This is a local, user-run security audit helper for checking other skill packages, with no evidence of hidden data export, persistence, or destructive behavior.
Install this if you want a simple local audit script for other skill packages. Run it on specific directories you intend to inspect, treat its findings as heuristic checks rather than proof of safety, and be aware that scan output may include file paths or matching lines from the scanned content.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal