File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed read-only integration guide for querying X data through Scavio’s API.
Install only if you are comfortable using Scavio as an intermediary for X lookups. Keep the API key out of source control, monitor credit usage before paginating through many pages, and verify that your use of public X profile or follower data fits your privacy and compliance needs.
63/63 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal