File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- README.md:47
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a legitimate defensive LLM proxy, but its main description overstates blocking protection compared with its documented async, fail-open behavior.
Review before installing if you plan to rely on this as a hard safety boundary. Test whether your chosen engine and mode actually block unsafe outputs before users or downstream tools see them, scope provider API keys carefully, review the upstream PyPI package, and disable or tightly control tracing for sensitive traffic.
48/48 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal