Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- grabber-enhanced.js:196
Security audit
Security checks across malware telemetry and agentic risk
Review before installing: this skill uses stealth web scraping, account cookies, external uploads, scheduled background jobs, and unsafe shell-command construction.
Install only if you are comfortable with automated scraping and external uploads. Avoid curl|bash, inspect the code first, disable cron and upload unless needed, use a dedicated low-privilege Gitee token, avoid personal Xianyu cookies, and require fixes for the shell-command injection issue before using untrusted keywords.
63/63 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command