File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- src/adapters/bluesky.ts:26
- Evidence
body: JSON.stringify({ identifier: BLUESKY_IDENTIFIER, password: [REDACTED] }),
Security audit
Security checks for vulnerabilities and agentic risk
This is a real content-publishing MCP, but account scoping, credential handling, and install metadata need review before use.
Install only if you intend to let an agent publish to your external accounts. Verify the package source before running because one config points to a different npm scope, use least-privilege tokens, protect ~/.distribution-mcp/profiles.yaml, avoid shared machines, and require your own review step before any publish, schedule, drain, or unpublish action.
Detected: suspicious.exposed_secret_literal
body: JSON.stringify({ identifier: BLUESKY_IDENTIFIER, password: [REDACTED] }),const apiKey = [REDACTED]["DEV_TO_API_KEY"];