File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:42
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward Threads data lookup integration that uses a Scavio API key and does not install code, persist data, or request unrelated authority.
Before installing, understand that queries go through Scavio using your SCAVIO_API_KEY and can consume credits; use it for public Threads lookups and avoid sending sensitive or unnecessary query data.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal