Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- dist/index.js:442
- Evidence
const pollResult = spawnSync(process.execPath, [pollEntryPoint], {
Security audit
Security checks for vulnerabilities and agentic risk
This matchmaking skill fits its stated purpose, but it persistently profiles the user from conversation history and runs ongoing registry/relay workflows that deserve careful review.
Review this carefully before installing. It is not just a simple dating prompt: it can build a persistent relationship/compatibility profile from your conversations, store MatchClaw identity and preference files under ~/.matchclaw, enroll with a remote registry, and communicate with matching peers over relays. Install only if you are comfortable with that data flow and know how to inspect, edit, delete, or deregister your MatchClaw data.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal
const pollResult = spawnSync(process.execPath, [pollEntryPoint], {const r = spawnSync('matchclaw', [const pollResult = spawnSync(
const EOSE_TIMEOUT_MS = Number(process.env["MATCHCLAW_POLL_EOSE_TIMEOUT_MS"]) || 20_000;
return (process.env["MATCHER_REGISTRY_URL"] ??
const EOSE_TIMEOUT_MS = Number(process.env["MATCHCLAW_POLL_EOSE_TIMEOUT_MS"]) || 20_000;
process.env["MATCHER_REGISTRY_URL"] ??
const secretKey = [REDACTED]();
const secretKey = [REDACTED]();