File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Target product-data helper that uses a disclosed Scavio API key and does not install code or persist access.
Before installing, understand that using the skill sends Target lookup requests to Scavio with your SCAVIO_API_KEY and consumes Scavio credits; keep the key in your environment or secret store and verify store-specific prices with the included product URLs.
Detected: suspicious.exposed_secret_literal