File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:37
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward guide for using Scavio to search App Store listings and reviews, with the expected need for an API key and network calls.
Before installing, understand that requests go to Scavio, use your SCAVIO_API_KEY, and may spend API credits. Use it when you are comfortable sending App Store search terms, app IDs, and review queries to that service.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal