File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:79
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed connector for AgentEarth external API tools, with clear credential and endpoint safeguards.
Before installing, confirm you trust AgentEarth with task queries and any parameters you ask it to process. Configure the API key through the host secret mechanism, and avoid sending sensitive tokens, private code, or account data unless that is intended for the selected external tool.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal