File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- references/decision-policy.md:11
Security audit
Security checks across malware telemetry and agentic risk
This skill is a coherent payment trust-gate integration with disclosed Valiron SDK usage and no evidence of hidden persistence, unrelated data access, or destructive behavior.
Before installing, review the @valiron/sdk package provenance, keep VALIRON_API_KEY in a secrets manager, test the decision policy and spend limits with representative payment routes, and use fail-closed defaults for production or high-value payment flows.
61/61 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal