File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks across malware telemetry and agentic risk
This skill is a read-only Target.com product-data integration that clearly discloses its external API use and credential requirement.
Before installing, understand that Target searches and product lookups will be sent to Scavio using your SCAVIO_API_KEY and will consume Scavio credits. Use a store_id only when store-specific pricing or availability is needed, since that can reveal the store context for the request.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal