Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- skills/writing-skills/render-graphs.js:25
Security audit
Security checks across malware telemetry and agentic risk
This appears to be a legitimate coding workflow skill, but it can automatically run hook scripts and read prior AI session logs, so it should be reviewed before enabling.
Install only if you are comfortable with persistent project memory files, possible reading of prior local AI session history, and automatic hook scripts. Before enabling it, inspect the installed hook paths, consider disabling session-catchup if not needed, avoid putting secrets in chat or planning files, and manually approve git/PR/destructive operations.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec