File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:32
Security audit
Security checks across malware telemetry and agentic risk
This skill is a coherent SocQ integration for researching public Google Ad Library data, with disclosed API-key, billing, polling, and export behavior.
Install only if you intend to use SocQ for Google Ad Library research and are comfortable providing a SocQ API key. Check credit costs before broad collection jobs, keep the API key out of prompts and URLs, and remember that raw task exports may contain larger result payloads than summarized output.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal