File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:38
Security audit
Security checks across malware telemetry and agentic risk
This skill is a read-only Douyin data connector that uses a disclosed Scavio API key and does not install code or add persistence.
Before installing, make sure you are comfortable giving the agent access to your Scavio API key and spending API credits. Use it for user-directed Douyin lookups, avoid tight search loops, and treat profiles/comments as real people's public content rather than material for personal profiling.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal