Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/index.cjs:14801
- Evidence
function spawn(command, args, options) {
Security audit
Security checks across malware telemetry and agentic risk
This is a disclosed security plugin that watches agent actions and scans installed plugins/skills; its higher-access behavior is purpose-aligned and user-configurable.
Install only if you want Sage to inspect agent commands, URLs, file operations, installed plugins, and skills. Review ~/.sage/config.json if you want to disable community telemetry, backend URL/file/package checks, or unknown skill uploads before use.
56/56 vendors flagged this plugin as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)
function spawn(command, args, options) {const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);const envDir = process.env.CLAUDE_CONFIG_DIR;
var debug = typeof process === "object" && process.env && process.env.NODE_DEBUG && /\bsemver\b/i.test(process.env.NODE_DEBUG) ? (...args) => console.error("SEM...bn = process.env.TESTING_TAR_FAKE_PLATFORM || process.platform;
"sourcesContent": ["import { randomBytes } from \"node:crypto\";\nimport * as fs from \"node:fs\";\nimport * as fsPromises from \"node:fs/promises\";\nimport { ..."sourcesContent": ["import { randomBytes } from \"node:crypto\";\nimport * as fs from \"node:fs\";\nimport * as fsPromises from \"node:fs/promises\";\nimport { ..."sourcesContent": ["/**\n * Detached worker that uploads unknown skills to the Skill Analyzer and caches\n * the verdicts. Reads its work list from the pending ...