File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:42
Security audit
Security checks across malware telemetry and agentic risk
This skill is a coherent G2 data lookup integration that discloses its Scavio API-key use and credit costs.
Before installing, understand that each API call spends Scavio credits and requires sending your SCAVIO_API_KEY to Scavio's API; otherwise the behavior is disclosed and purpose-aligned for G2 product and review research.
62/62 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal