File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:37
Security audit
Security checks across malware telemetry and agentic risk
This skill is a clearly disclosed wrapper for querying public GitHub data through Scavio, with no hidden install scripts or persistence.
Before installing, be aware that use requires a Scavio API key and consumes Scavio credits. Queries and public GitHub identifiers are sent to Scavio, and the public commit email endpoint can return personal data, so use that endpoint only for legitimate, user-directed purposes.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal