Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- index.js:268
Security audit
Security checks across malware telemetry and agentic risk
The skill has a coherent self-evolution purpose, but it also includes high-impact background, network, update, validation, and credit-spending behavior that needs manual review before installation.
Install only if you are comfortable with a self-evolving background agent. Before connecting it to EvoMap Hub or running loop mode, review the obfuscated-package tradeoff, disable features you do not want such as ATP auto-spend and validator mode, avoid providing a GitHub token unless needed, and use review mode or a non-critical git workspace first.
SkillSpector could not complete.
1/62 vendors flagged this skill as malicious, and 61/62 flagged it as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+4 more)