Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- index.js:428
Security audit
Security checks across malware telemetry and agentic risk
This skill has a coherent agent-evolution purpose, but its high-impact daemon, hook, network, and working-tree mutation behavior is under-disclosed and much of the core logic is obfuscated.
Review carefully before installing. Use this only in a disposable or well-versioned git workspace unless you are comfortable with an agent-evolution daemon that can install host-runtime hooks, read project/session history, contact EvoMap Hub, store local secrets, and modify or roll back working-tree changes. Set opt-out environment variables such as EVOLVE_BRIDGE=false, EVOLVER_VALIDATOR_ENABLED=0, and MEMORY_GRAPH_SYNC_HUB=0 where appropriate, and inspect generated hooks before enabling them.
SkillSpector could not complete.
1/62 vendors flagged this skill as malicious, and 61/62 flagged it as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+4 more)