File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/src/config.js:61
- Evidence
apiKey: [REDACTED] || process.env[apiKeyEnv],
Security audit
Security checks for vulnerabilities and agentic risk
The plugin appears aligned with its video-generation purpose, but users should notice that it uses paid external model APIs, stores reusable local project assets, and has a minor dependency-lockfile mismatch to review.
Install only if you are comfortable sending story/reference content to the configured model providers and using their API quota. Keep keys in environment variables, review the output/workspace directory for retained assets, and check the lockfile/dependencies before running pnpm install.
Detected: suspicious.exposed_secret_literal
apiKey: [REDACTED] || process.env[apiKeyEnv],
apiKey: [REDACTED],
const apiKey = [REDACTED](prepared.config);
apiKey: [REDACTED] || process.env[apiKeyEnv],
apiKey: [REDACTED],
const apiKey = [REDACTED](prepared.config);