Back to skill

Security audit

kids-points

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches a children’s points tracker, but its voice feature appears to run shell commands built from user or spoken text and stores child-related data persistently, so it should be reviewed before installation.

Review the voice implementation before installing or enabling audio features. In particular, avoid using the skill until TTS shell execution is made safe, confirm where child photos and ledgers will be stored, and only configure SENSE_API_KEY or helper skills if you trust the external voice provider and dependencies.

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/handler.js:481