File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- references/capabilities.md:76
Security audit
Security checks across malware telemetry and agentic risk
This skill is a disclosed VMware Aria Operations monitoring and reporting integration with limited, purpose-aligned write actions.
Before installing, confirm you trust the PyPI/GitHub package, use the least-privileged Aria service account that fits your needs, keep `.env` permissions at 600, and reserve PowerUser-style credentials only for users who should be able to acknowledge/cancel alerts, manage alert definitions, or delete generated reports.
64/64 vendors flagged this skill as clean.
Detected: suspicious.exposed_secret_literal