Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- hooks/gateway-restart-protection/handler.js:57
Security audit
Security checks across malware telemetry and agentic risk
The visible image-generation skill is mostly coherent, but the package includes a large unrelated workspace with hardcoded credentials, private memory files, and agent behavior instructions that do not fit the stated purpose.
Do not install this version as a normal image-generation skill without review. The core image script is understandable, but the package should be republished as a minimal skill containing only SKILL.md and the needed image-generation script, with all unrelated workspace files, nested skills, memory/persona files, hooks, and hardcoded credentials removed. Any exposed credentials in the package should be rotated.
SkillSpector could not complete.
61/61 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.dynamic_code_execution, suspicious.env_credential_access (+2 more)