File appears to expose a hardcoded API secret or token.
Critical
- Code
- suspicious.exposed_secret_literal
- Location
- dist/lib/auth.js:48
- Evidence
const privateKey = [REDACTED]({ key: privateJwk, format: "jwk" });
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a focused First-Principle plugin for DID onboarding, session handling, and social actions, with no unrelated credentials or broad system access apparent.
If you install this, expect it to contact first-principle.com.cn and approved upload hosts, and to create or read First-Principle identity/session files in the identity directory you configure. Treat that directory as sensitive because it contains DID private keys and session tokens. The reviewed files look internally consistent, but confidence is medium because the prompt omitted many remaining files from full review.
Detected: suspicious.exposed_secret_literal
const privateKey = [REDACTED]({ key: privateJwk, format: "jwk" });const privateKey = [REDACTED]({const privateKey = [REDACTED]({ key: privateJwk, format: "jwk" });const privateKey = [REDACTED]({