Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/security_scan.py:64
Security audit
Security checks across malware telemetry and agentic risk
This is a coherent local vulnerability-scanning skill that reads user-selected project files and optionally runs npm audit, with no evidence of hidden persistence, exfiltration, or destructive behavior.
Install only if you intend to run local security scans. Point it at specific projects, not broad home directories, and treat the output as sensitive because it can mention secret types, paths, and vulnerability details. Be aware that npm audit may use your npm configuration and contact npm services for JavaScript projects.
66/66 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution