Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- bin/skillhub-launcher.mjs:182
- Evidence
const child = spawn(binaryPath, process.argv.slice(2), {
Security audit
Security checks across malware telemetry and agentic risk
No artifact-backed suspicious behavior could be identified, but the workspace files could not be read in this run.
Treat this as an incomplete review: the available telemetry alone does not justify a suspicious or malicious verdict, but the package should be re-scanned when metadata.json and artifact contents can be inspected.
VirusTotal engine telemetry is currently stale for this artifact.
Detected: suspicious.dangerous_exec, suspicious.install_untrusted_source
const child = spawn(binaryPath, process.argv.slice(2), {"SKILLHUB_DISCOVERY_HOST": "http://218.11.5.155:8399"