File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- secret.md:6
Security audit
Security checks across malware telemetry and agentic risk
This skill does not run code, but it published a file it explicitly says should be excluded, and that file contains secret-like placeholder data.
Review before installing or distributing. The publisher should remove secret.md, verify the ignore rules, and republish; if any real secret was ever included in this file, rotate it.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal