File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- SKILL.md:39
Security audit
Security checks for vulnerabilities and agentic risk
This is a straightforward documentation-only skill for using a paid Yelp-style business data API.
Install only if you are comfortable sending business search queries to yelp.fetcher.sh and using either a Fetcher Bearer key or x402 payment. Review the pricing, refund limitation, and any wallet or credit top-up action before allowing paid calls.
Detected: suspicious.exposed_secret_literal