File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:23
Security audit
Security checks across malware telemetry and agentic risk
This skill is a straightforward guide for adding an AINative chat SDK to Svelte apps, with expected external API use and no hidden execution or persistence.
Before installing, confirm you trust the @ainative/svelte-sdk npm package and AINative as a service provider. Keep real secret keys server-side, use only scoped public keys in browser code, and make sure users know their chat messages may be sent to AINative.
66/66 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal