Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- src/extract.ts:1089
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears to be a coherent static permission scanner; it reads a chosen skill folder and writes a manifest, with no artifact-backed evidence of credential theft, hidden network exfiltration, or unsafe automatic execution.
This skill looks safe to use for its stated purpose if you run it on a specific skill directory you intend to review. Verify the npx package/provenance before execution, avoid pointing it at broad private folders, and protect or delete permission-manifest.json if it contains sensitive paths, domains, commands, or env var names.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+1 more)