File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:36
Security audit
Security checks across malware telemetry and agentic risk
This skill is a clearly scoped Yelp data lookup helper that uses a disclosed Scavio API key and credit-based external API.
Before installing, be comfortable using a third-party Scavio API key, sending Yelp lookup queries to Scavio, and spending credits per request. Keep the API key out of source control and verify important business or review data against the returned Yelp URL.
61/61 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal