File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- index.js:17
Security audit
Security checks across malware telemetry and agentic risk
The parser is simple, but it embeds a SkillPay API key and automatically charges an external billing service whenever it runs.
Do not install until the exposed SkillPay key is rotated and removed, and until billing behavior clearly requires your consent for each paid request. If you do install it, assume each invocation may contact SkillPay and charge the configured per-request fee.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal