File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:40
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward third-party URL extraction helper with its API-key use, pricing, limits, and guardrails clearly disclosed.
Install this only if you are comfortable sending the URLs you ask it to fetch, and resulting page content, to Scavio under your API key and credit balance. Avoid using it for private or sensitive URLs unless that sharing is intended.
45/45 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal