File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:332
Security audit
Security checks across malware telemetry and agentic risk
This skill is a normal NestJS and TypeORM setup guide, with database-change and example-password cautions but no hidden or unrelated behavior.
Before using this skill, review generated migrations before running them, test database changes outside production, and replace example database credentials with real secrets stored in environment variables or a secret manager.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal