Exposed secret literal
Critical
- Finding
- File appears to expose a hardcoded API secret or token.
- Skill content
const { message, token, account, config, runtime, core, mediaPath, mediaType, statusSink, fetcher, authorization: [REDACTED] } = params;
Security checks across static analysis, malware telemetry, and agentic risk
No risk analysis has been recorded yet.
SkillSpector findings are pending for this release.
const { message, token, account, config, runtime, core, mediaPath, mediaType, statusSink, fetcher, authorization: [REDACTED] } = params;62/62 vendors flagged this plugin as clean.
No visible risk-analysis findings were reported for this release.