Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- index.js:11
- Evidence
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/data/seo'
Security audit
Security checks for vulnerabilities and agentic risk
This plugin coherently provides disclosed SEO research tools backed by the superagnt API, with no hidden install behavior or unrelated capabilities found.
Install only if you intend to use superagnt for SEO data and are comfortable providing a superagnt API key. Queries, domains, URLs, and keyword lists you submit through the tools will be sent to the superagnt API, and usage may consume paid quota.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
const BASE_URL = (process.env.SUPERAGNT_API_URL || 'https://api.superagnt.com') + '/v1/data/seo'