File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:37
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward AliExpress data lookup integration that uses a Scavio API key and does not add hidden execution or persistence.
Install this if you are comfortable using Scavio as a third-party API provider for AliExpress research. Keep the SCAVIO_API_KEY in your environment or secret store, monitor credit usage, and avoid sending sensitive business queries unless that fits your data-sharing expectations.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal