New Research: Supply Chain Attack on Axios Pulls Malicious Dependency from npm.Details →
Socket
Book a DemoSign in
Socket

Skill: Hardcoded secrets

Severity

High

Short Description

AI agent skill contains hardcoded API keys, tokens, private keys, or other credentials that could be exploited if the skill is distributed.

Suggestion

Review the skill's code and behavior carefully. Ensure the detected patterns are intentional and safe before allowing this skill to run.