File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:38
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward Douyin data API guide that uses a disclosed Scavio API key and does not install code, persist state, or request unusual local access.
Install only if you are comfortable sending Douyin lookup requests to Scavio with your API key. Watch credit costs, especially search endpoints, and use the returned public social data responsibly and in line with applicable platform rules and privacy expectations.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal