File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:38
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed SEC EDGAR lookup integration that uses a Scavio API key to query public filing data.
Before installing, confirm you are comfortable sending SEC filing queries to Scavio and using credits on each endpoint call. Store SCAVIO_API_KEY like any other API credential. The skill is for public regulatory data and should not be treated as investment advice.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal