File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- references/common/design-principles.md:149
Security audit
Security checks across malware telemetry and agentic risk
This is a documentation-only API design skill with normal examples and no evidence of hidden execution or data collection.
Safe to install for API design help. Treat bundled tokens, passwords, URLs, and shell commands as examples only; replace placeholders before use and run optional documentation-tool commands only when you intentionally want those tools.
63/63 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal