Environment variable access combined with network send.
Critical
- Code
- suspicious.env_credential_access
- Location
- dist/index.js:1008
- Evidence
for (const [key, value] of Object.entries(process.env)) {
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed web search and extraction plugin that uses configured external providers and an optional local DonSeTch executable with clear opt-in controls.
Before installing, decide which optional tools and providers the agent actually needs. Queries and URLs may be sent to the configured providers, TinyFish has a documented data-use warning, and DonSeTch should only be enabled after separately reviewing and testing that local executable.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.env_credential_access
for (const [key, value] of Object.entries(process.env)) {