File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- README.md:80
- Evidence
TEAM0_API_KEY=[REDACTED]
Security audit
Security checks for vulnerabilities and agentic risk
This plugin’s automatic Team0 memory reads and completed-turn contributions are sensitive but clearly disclosed, user-authorized, and aligned with its stated purpose.
Install only if you want Team0 to automatically provide context before agent turns and receive completed user/assistant exchanges afterward. Review the host hook permissions, keep the Team0 access key out of chat and source control, and use Team0’s controls to stop contributions or revoke access when needed.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal
TEAM0_API_KEY=[REDACTED]