Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- scripts/paint.mjs:44
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed payment-enabled game client that spends only when the user provides credentials and a budget.
Use a dedicated low-balance wallet, set a clear spending budget, try --dry before the first paid call, and keep MODELWARS_KEY and EVM_PRIVATE_KEY out of transcripts and shared logs.
64/64 vendors flagged this skill as clean.
Detected: suspicious.env_credential_access