File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:36
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward Scavio/Yelp API guide that uses a user-provided API key to fetch public business and review data, with costs and limits disclosed.
Before installing, understand that your Yelp queries are sent to Scavio and each API call consumes credits. Keep SCAVIO_API_KEY private and budget review pagination carefully.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal