File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:27
Security audit
Security checks for vulnerabilities and agentic risk
This skill coherently helps configure and use ViralQuery’s API, with credential handling and API calls disclosed and scoped to the stated research workflow.
Before installing, be comfortable letting the agent use a ViralQuery API key and send your research brief, rules, prompts, and resulting source queries to ViralQuery. Prefer an environment secret store, verify the API URL, and only enable recurring research when you explicitly want scheduling.
Detected: suspicious.exposed_secret_literal