File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:37
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a straightforward Scavio API guide for reading Weibo data, with the API key and credit costs disclosed.
Before installing, understand that this skill sends requests to Scavio's external API, uses your SCAVIO_API_KEY, and spends credits per request. Avoid using it to profile individuals; keep the API key out of source control and only run queries you intend to pay for.
Detected: suspicious.exposed_secret_literal