File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:37
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed GitHub public-data lookup wrapper around Scavio's API and does not include hidden code or persistence.
Install only if you are comfortable using a Scavio API key and sending GitHub usernames, repository names, issue URLs, and search queries to Scavio. Be especially careful with the public commit email endpoint because it returns personal data, even though the skill discloses this and warns against profiling individuals.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal