File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:43
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed wrapper guide for using a third-party Kuaishou data API and does not show hidden execution, persistence, or unrelated data access.
Before installing, understand that queries go to Scavio's API using your SCAVIO_API_KEY and can spend credits, especially search and batch endpoints. Use it only for Kuaishou China data and keep the API key in your environment or secret store rather than source files.
Detected: suspicious.exposed_secret_literal