File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:35
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward third-party API skill for fetching Google AI Mode answers through Scavio, with its required API key and per-request cost disclosed.
Before installing, understand that your queries will be sent to Scavio's API and each successful call uses credits. Keep SCAVIO_API_KEY out of source control, avoid sending sensitive private information in queries, and verify important answers using the returned references.
Detected: suspicious.exposed_secret_literal