T09 · Insecure Skill Coding Practices
- Location
SKILL.md:56- Finding
API Credential Exposed Through Command-Line URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill makes a disclosed call to The Odds API to retrieve sports odds data and does not show hidden behavior, persistence, or unrelated data access.
Before installing, understand that the skill requires an API key for The Odds API and sends that key to api.the-odds-api.com when commands are run. Avoid enabling shell tracing or logging full command lines, rotate the key if it may have been logged, and consider tightening API quotas or permissions where the provider allows it.
SKILL.md:56API Credential Exposed Through Command-Line URL
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Show which sports currently have odds:
curl -s "https://api.the-odds-api.com/v4/sports?apiKey=$ODDS_API_KEY" \
| jq '[.[] | select(.active==true) | {key, title, description}]'
## About
No suspicious patterns detected.