Back to skill

Security audit

Evolver

Security checks for vulnerabilities and agentic risk

Overview

This appears to be a real Evolver tool, but it needs Review because it enables persistent networked automation and default remote validation code execution that is not safely scoped or fully disclosed.

Review before installing. Only use this skill if you are comfortable with a global CLI that can install persistent agent hooks, read/write local evolution state, contact EvoMap/GitHub, and run Hub-assigned validator jobs. Set EVOLVER_VALIDATOR_ENABLED=false unless you explicitly want remote validation work, disable telemetry if unwanted, and avoid running it in a workspace or user account that has sensitive files or credentials.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (5)

T09 · Insecure Skill Coding Practices

Error
Location
src/gep/validator/sandboxExecutor.js:243
Finding

Hub-Provided Validation Commands Execute Without OS-Level Sandbox Isolation

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
src/gep/validator/index.js:25
Finding

Remote Validator Role Is Enabled by Default and Can Be Controlled Through Persisted Feature State

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
src/config.js:228
Finding

Default-On Anti-Abuse Telemetry Is Not Declared in the Skill Configuration

Content
View full analysis
fallback // above): a blank `EVOLVER_ANTI_ABUSE_TELEMETRY=` line in a .env file must // not silently disable the documented default-on behavior. Opt-out is // explicit only. if (v === '') return 'heartbeat'; if (v === '0' || v === 'false' || v === 'no' || v === 'off') return 'off'; return (v === '1' || v === 'true' || v === 'yes' || v === 'on' || v === 'heartbeat') ? 'heartbeat' : 'off'; } ``` ### Technical Analysis The configuration explicitly enables an anti-abuse metadata envelope by default. An unset or blank environment variable resolves to `heartbeat`, so users must know about the feature and explicitly disable it. The audited `SKILL.md` environment declarations do not include `EVOLVER_ANTI_ABUSE_TELEMETRY`. Consequently, the default network behavior is not fully represented in the Skill’s permission and configuration disclosure. The source describes the data as hashes and source-confidence labels. Hashing does not necessarily anonymize stable or low-entropy attributes: values drawn from a limited domain may be guessed through dictionary enumeration, and stable hashes may allow activity correlation across heartbea ...[truncated 1071 chars]
Remediation
View remediation

other

Warning
Location
src/evolve.js:1
Finding

Security-Critical Hub and Evolution Modules Are Distributed as Obfuscated JavaScript

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
index.js:2345
Finding

Direct Authenticated Hub Request Contradicts the Declared Proxy-Only Security Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6977)

Intent-Code Divergence

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The 'does not do' list says Evolver does not execute arbitrary shell commands. Later, the security model explicitly states that src/gep/solidify.js executes Gene validation commands and that distributed validator mode runs proposer-declared validation commands in a sandbox. This is an active contradiction in the documentation, not mere omission.

Content

No source excerpt is available for this finding.

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.ja-JP.md (reported line 81)May include surrounding context.

变更范围计算和固化(solidify)。在非 git 目录中运行会直接报错并退出。

从 npm 安装(推荐)

bash
npm install -g @evomap/evolver

此命令将全局安装 evolver CLI。通过 evolver --help 验证。

如在 Linux/macOS 上遇到 EACCES 错误,建议配置用户级 prefix,而不是使用 sudo:

bash
npm config set prefix ~/.npm-global
echo 'export PATH="$HOME/.npm-global/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

平台集成

Evolver 通过 setup-hooks 命令与主流 Agent 运行时集成。每个需要接入的平台执行一次即可。

Cursor

bash
evolver setup-hooks --platform=cursor

会写入 ~/.cursor/hooks.json,并将 hook 脚本安装到 ~/.cursor/hooks/。重启 Cursor(或开新会话)后生效。钩子在 sessionStart、afterFileEdit、stop 时触发。

Claude Code

bash
evolver setup-hooks --platform=claude-code

通过 ~/.claude/ 向 Claude Code 的 hook

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.ko-KR.md (reported line 80)May include surrounding context.

变更范围计算和固化(solidify)。在非 git 目录中运行会直接报错并退出。

从 npm 安装(推荐)

bash
npm install -g @evomap/evolver

此命令将全局安装 evolver CLI。通过 evolver --help 验证。

如在 Linux/macOS 上遇到 EACCES 错误,建议配置用户级 prefix,而不是使用 sudo:

bash
npm config set prefix ~/.npm-global
echo 'export PATH="$HOME/.npm-global/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

平台集成

Evolver 通过 setup-hooks 命令与主流 Agent 运行时集成。每个需要接入的平台执行一次即可。

Cursor

bash
evolver setup-hooks --platform=cursor

会写入 ~/.cursor/hooks.json,并将 hook 脚本安装到 ~/.cursor/hooks/。重启 Cursor(或开新会话)后生效。钩子在 sessionStart、afterFileEdit、stop 时触发。

Claude Code

bash
evolver setup-hooks --platform=claude-code

通过 ~/.claude/ 向 Claude Code 的 hook

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.md (reported line 86)May include surrounding context.

变更范围计算和固化(solidify)。在非 git 目录中运行会直接报错并退出。

从 npm 安装(推荐)

bash
npm install -g @evomap/evolver

此命令将全局安装 evolver CLI。通过 evolver --help 验证。

如在 Linux/macOS 上遇到 EACCES 错误,建议配置用户级 prefix,而不是使用 sudo:

bash
npm config set prefix ~/.npm-global
echo 'export PATH="$HOME/.npm-global/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

平台集成

Evolver 通过 setup-hooks 命令与主流 Agent 运行时集成。每个需要接入的平台执行一次即可。

Cursor

bash
evolver setup-hooks --platform=cursor

会写入 ~/.cursor/hooks.json,并将 hook 脚本安装到 ~/.cursor/hooks/。重启 Cursor(或开新会话)后生效。钩子在 sessionStart、afterFileEdit、stop 时触发。

Claude Code

bash
evolver setup-hooks --platform=claude-code

通过 ~/.claude/ 向 Claude Code 的 hook

YARA rule 'backdoor_persistence': Backdoor persistence with malicious payloads (shell commands, SSH key injection, hidden root users) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · README.zh-CN.md (reported line 78)May include surrounding context.

变更范围计算和固化(solidify)。在非 git 目录中运行会直接报错并退出。

从 npm 安装(推荐)

bash
npm install -g @evomap/evolver

此命令将全局安装 evolver CLI。通过 evolver --help 验证。

如在 Linux/macOS 上遇到 EACCES 错误,建议配置用户级 prefix,而不是使用 sudo:

bash
npm config set prefix ~/.npm-global
echo 'export PATH="$HOME/.npm-global/bin:$PATH"' >> ~/.bashrc
source ~/.bashrc

平台集成

Evolver 通过 setup-hooks 命令与主流 Agent 运行时集成。每个需要接入的平台执行一次即可。

Cursor

bash
evolver setup-hooks --platform=cursor

会写入 ~/.cursor/hooks.json,并将 hook 脚本安装到 ~/.cursor/hooks/。重启 Cursor(或开新会话)后生效。钩子在 sessionStart、afterFileEdit、stop 时触发。

Claude Code

bash
evolver setup-hooks --platform=claude-code

通过 ~/.claude/ 向 Claude Code 的 hook

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description captures only a subset of the code's behavior. While the code does include an evolution loop and hub/proxy-related functionality consistent with a self-evolution engine, this chunk is actually the main operational entrypoint for a large multi-function daemon/CLI. It includes bootstrap update recovery, singleton locking, process lifecycle management, token credential helper behavior, git review/rollback/solidify flows, remote skill download, and ATP/validator/background services. Most notably, the proxy-token path exposes a local credential helper that reads and outputs a proxy token, which is a sensitive capability not suggested by the description. The code also performs substantial shell/git and filesystem actions beyond merely analyzing runtime history and applying constrained evolution. Therefore the description materially understates and misrepresents the skill's actual capabilities and primary scope.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents a narrow primary purpose: an AI self-evolution engine that analyzes runtime history and evolves protocols, communicating with EvoMap Hub through a local proxy mailbox. The actual code chunk instead exposes a broad multi-command CLI for marketplace, asset management, authentication, web UI, hook management, secret reset, trajectory export, recipe handling, ATP transaction flows, and experiment execution. Some pieces are adjacent to an evolution platform, but the implemented behavior is materially broader and operationally different from the declared purpose. In particular, the code performs substantial account/auth, local system configuration, file export/import, web serving, and transaction-related actions that are not conveyed by the description. The declared network and shell permissions are not themselves problematic, but the description understates the true scope and capabilities of the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code does not implement a self-evolution engine. It reads preexisting genes, capsules, and events from storage, filters them for A2A export, formats them as JSON or protocol messages, and optionally sends those messages through a transport. While it does communicate outward via a transport/mailbox-like mechanism, that communication is in service of exporting/publishing assets. There is no logic for analyzing runtime history to derive improvements, selecting or applying evolutionary changes, or modifying agent protocols. Thus the declared description materially overstates and mischaracterizes the code's primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The code chunk is a focused ingestion utility for external A2A data. It reads text input, parses candidate objects, filters allowed assets, verifies content-hash-based asset IDs, reduces confidence for external sources, stores staged candidates, records them in a memory graph, and optionally sends reject/quarantine decisions. This is materially different from the declared purpose of a self-evolution engine that analyzes runtime history and applies constrained evolution. While some persistence and transport behavior could be supporting infrastructure, the primary behavior shown is intake and quarantine of external assets, not agent self-improvement.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
94% confidence
Finding

The code’s primary function is a command-line asset promotion script, not an engine that analyzes agent runtime history and evolves the agent. It requires explicit --type, --id, and --validated inputs, loads recent external candidates, performs limited safety checks on Gene validation commands, marks the chosen asset as promoted, stores it locally, and may optionally send decision messages. While the description mentions protocol-constrained evolution and communication with a hub, the actual code does not analyze history, generate improvements, or perform evolution decisions beyond promoting a preexisting candidate. The optional A2A transport messaging is secondary and much narrower than the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The code is a local analysis/report generator. It reads evolution_history_full.md, extracts interesting entries, groups them by skill, and writes evolution_detailed_report.md. While this loosely relates to analyzing history, it does not identify improvements in any decision-making sense beyond simple keyword filtering, does not perform protocol-constrained evolution, and does not communicate with any hub, proxy, mailbox, network, or shell. The primary purpose described is materially broader and different from the actual behavior shown.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code is a packaging/build script, not an AI self-evolution engine. Its behavior is narrowly focused on local filesystem and shell-based build operations: checking tool availability, bundling JavaScript with Bun, optionally obfuscating code, compiling platform-specific executables, generating SHA256 checksum files, and smoke-testing the host binary. There is no logic for analyzing runtime history, modifying agent protocols, evolving behavior, or communicating with any EvoMap Hub or local Proxy mailbox. While the declared permissions include shell and network, the script does not actually implement the claimed networked agent-evolution functionality. This is a material description-versus-behavior mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description and the code behavior are materially unrelated. The code is a release-process utility that validates frozen CHANGELOG sections against git tags using local file reads and git commands. It does not analyze runtime history, evolve agents, apply protocols for evolution, or communicate with any hub/mailbox. While declared permissions include network and shell, only local shell/git and filesystem access are used; over-declared permissions alone are not the issue. The primary purpose is clearly different, so this is a strong mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The supplied code is a standalone log-extraction utility. It reads memory/mad_dog_evolution.log, parses 'Cycle Start' timestamps and Feishu-card command lines, converts them into markdown, and writes evolution_history.md. It does not analyze runtime history for improvements in any substantive sense beyond extracting logged text, does not apply any evolution changes, and does not communicate with any hub or mailbox. Therefore the actual behavior is materially narrower and different from the declared purpose.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description presents a sophisticated self-evolution engine with analysis, decision-making, and external/local mailbox communication. The supplied code does none of that. It simply invokes git log, filters commit messages by the keyword "Evolution", reformats the results, and saves them as a markdown report. While this could be tangentially related to documenting evolution history, its primary purpose and capabilities are materially narrower and different from the declared functionality. There is no evidence of runtime-history processing, applying changes/evolution, or network/proxy mailbox communication.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description presents an active self-evolution component with analysis, improvement application, and hub communication. The supplied code only reads local JSON/JSONL files, computes aggregate metrics for personality states from EvolutionEvent records, and prints a summary report. There is no code to modify agent state, enact protocol-constrained evolution, send messages, access a mailbox, or use network/shell capabilities. This is a materially different primary purpose: diagnostic/report generation rather than agent self-evolution.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents this skill as an active self-evolution engine with analysis, improvement application, and hub communication. The supplied code instead implements a report generator: it reads evolution_history_full.md, parses entries, classifies them into categories/components using keyword matching, builds a markdown summary, and writes evolution_human_summary.md. There is no evidence of agent evolution, runtime decision-making, protocol-constrained updates, shell usage, network access, or mailbox/proxy communication. This is a materially different primary purpose, so it should be flagged as a mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code is a standalone Node.js report generator for recall_verify events. It parses CLI args, reads local memory graph events via tryReadMemoryGraphEvents, computes success/mismatch statistics and percentiles, prints Markdown/JSON, and returns exit code 0 or 2 based on thresholds. It does not analyze runtime history for improvement opportunities in the sense of evolving an agent, does not apply any changes or protocol-constrained evolution, and does not communicate with EvoMap Hub or a local Proxy mailbox. The declared description therefore materially misrepresents both the primary purpose and the capabilities of this code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description and the actual code behavior are materially unrelated. The description claims an AI self-evolution component involving runtime analysis, agent improvement logic, and mailbox-based hub communication. The supplied code instead performs a narrow release/maintenance task: it reads README markdown files, fetches GitHub stargazer counts, formats the number, and rewrites static shields.io badge text. While the declared permissions include network and shell, which the script does use through HTTPS and the gh CLI, those are over-declared/supporting details rather than evidence of purpose alignment. The primary purpose, accessed resources, and functionality do not match the declared description.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description describes an autonomous self-improvement system for AI agents. The actual code does not analyze runtime history, evolve agents, or enforce any evolution protocol. Instead, it bootstraps a merchant agent with three predefined service listings and handles incoming orders with simple keyword-based canned outputs. It communicates with a hub URL through a merchant agent, not via a local Proxy mailbox as described. This is a clear material mismatch in primary purpose and capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The code is a command-line utility named skill2recipes. It parses flags like --manifest, --title, --price, and --no-publish, loads a JSON manifest or skill paths from disk, and calls composeRecipeFromSkills to build and optionally publish a recipe to EvoMap. It sets A2A_TRANSPORT='http' and defaults A2A_HUB_URL to https://evomap.ai, indicating direct network communication to the Hub. There is nothing in this code about analyzing runtime history, identifying agent improvements, or applying self-evolution constraints. The primary purpose is materially different from the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The code is a release/versioning utility, not an AI self-evolution engine. Its primary function is to inspect git commit messages and current package version, determine a semver bump (major/minor/patch), and persist that suggestion locally. While it uses shell access for git commands and filesystem writes, these are in service of version suggestion only. There is no network use, no mailbox/hub communication, no runtime-history analysis of an agent, and no application of behavioral or protocol changes. This is a clear material mismatch in primary purpose and declared capabilities.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a sophisticated AI self-evolution component with analysis, improvement, and local hub communication capabilities. The supplied code does none of that. It is a simple developer utility script for validating JavaScript modules by requiring them and checking their exports. There is no evidence of runtime-history processing, evolution logic, network or mailbox communication, or any AI-agent behavior. The primary purpose is materially different, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The supplied code does not implement an AI self-evolution engine or any of the described behaviors. It simply validates and runs JavaScript test files using node --test, manages environment variables for the test process, and reports test results. There is no network activity, no mailbox communication, no analysis of runtime history, and no application of agent evolution logic. The primary purpose is materially different from the declared description, so this is a clear mismatch.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The declared description presents the skill as an autonomous self-evolution engine with analysis and hub communication responsibilities. The supplied code chunk instead implements a platform adapter for Claude Code: it builds hook definitions, writes settings, copies scripts, injects/removes a markdown section, and uninstalls those changes. While these hooks may support a larger evolver system, this chunk’s actual behavior is installation/configuration management, not the declared core behavior. The declared triggers are also inconsistent with the concrete hook events configured by the code.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+4 more)

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
index.js:428

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/build_binaries.js:120

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/generate_history.js:17

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/recover_loop.js:54

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/refresh_stars_badge.js:78

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/suggest_version.js:27

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/validate-suite.js:50

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/adapters/hookAdapter.js:89

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/adapters/scripts/evolver-session-end.js:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/adapters/scripts/evolver-session-start.js:144

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/experiment/agentRunner.js:169

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/forceUpdate.js:268

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/gitOps.js:17

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/idleScheduler.js:84

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/llmReview.js:70

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/selfPR.js:18

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/signals.js:334

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/gep/validator/sandboxExecutor.js:32

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/lifecycle.js:38

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/self_repair.js:21

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/ops/skills_monitor.js:100

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
src/solo/gitGuard.js:11

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/a2aProtocol.test.js:1149

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/adapters.test.js:1134

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/adaptersSyntax.test.js:40

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/autoDistillConv.test.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/bridge.test.js:116

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/checkChangelog.test.js:72

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/evolveCollect.test.js:174

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/forceUpdateMidCopyWedge.test.js:248

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/lifecycleProxyHealth.test.js:14

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/loopMode.test.js:212

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/paths.test.js:609

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/proxySettings.test.js:87

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/recallVerifyReport.test.js:191

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/resetLocalSecret.test.js:34

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/resolveWorkspaceId.test.js:25

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/rollbackSafety.test.js:26

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/sessionEndHook.test.js:22

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/sessionStartScope.test.js:19

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/signals.test.js:486

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/solidifyIntegration.test.js:62

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/soloMode.test.js:44

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/spawnReplacementProcess.test.js:157

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/sync-dedup.test.js:62

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/trajectoryExport.test.js:1340

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/trajectoryMarkedSessionGate.test.js:54

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
test/validateSuite.test.js:27

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
src/webui/client/vendor/echarts.min.js:45

Dynamic code execution detected.

Critical
Code
suspicious.dynamic_code_execution
Location
test/adapters.opencode.test.js:123

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/gep/issueReporter.js:41

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
src/proxy/index.js:152

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/a2aProtocol.test.js:8

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/hubUrlTlsEnforcementConsistency.test.js:23

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyChatCompletionsE2E.test.js:41

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyClientsE2E.test.js:56

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyGeminiE2E.test.js:53

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyTokenReuse.test.js:66

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyTraceIntegration.test.js:88

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/proxyVertexE2E.test.js:39

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/v1Messages.test.js:62

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
test/v1Responses.test.js:52

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
index.js:3612

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
src/gep/signals.js:293

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/cliContracts.test.js:1424

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyAnthropic.test.js:160

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyChatCompletionsE2E.test.js:59

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyClientsE2E.test.js:79

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyGeminiE2E.test.js:70

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyGeminiUpstream.test.js:79

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyHubFetchRouting.test.js:51

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyModelsE2E.test.js:39

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyOllamaE2E.test.js:55

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyOpenAIResponses.test.js:129

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyTokenReuse.test.js:307

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/proxyVertexE2E.test.js:56

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/sanitize.test.js:79

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/trajectoryExport.test.js:1742

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/v1Responses.test.js:92

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
test/webuiObserver.test.js:215

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
test/hubFetch.test.js:9

HTTPS certificate verification is disabled.

Warn
Code
suspicious.insecure_tls_verification
Location
test/hubUrlTlsEnforcementConsistency.test.js:186

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/guards.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/collect.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/dispatch.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/enrich.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/hub.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/select.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/pipeline/signals.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/evolve/utils.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/a2aProtocol.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/antiAbuseTelemetry.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/autoDistillConv.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/autoDistillLlm.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/candidateEval.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/candidates.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/contentHash.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/conversationDistiller.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/conversationSniffer.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/crypto.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/curriculum.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/deviceId.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/envFingerprint.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/epigenetics.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/execBridge.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/explore.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/hash.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/hubFetch.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/hubReview.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/hubSearch.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/hubVerify.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/learningSignals.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/memoryGraph.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/memoryGraphAdapter.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/mutation.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/narrativeMemory.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/openPRRegistry.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/personality.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/policyCheck.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/prompt.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/recallInject.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/recallVerifier.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/reflection.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/savingsCore.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/selector.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/skillDistiller.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/solidify.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/strategy.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/tokenSavings.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/trajectoryExport.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/gep/workspaceKeychain.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/proxy/extensions/traceControl.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/proxy/inject.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/proxy/trace/extractor.js:1

Potential obfuscated payload detected.

Warn
Code
suspicious.obfuscated_code
Location
src/proxy/trace/usage.js:1

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
test/a2aProtocol.test.js:692

Sensitive-looking file read is paired with a network send.

Warn
Code
suspicious.potential_exfiltration
Location
test/proxyTraceIntegration.test.js:189