Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- bin/ldm.js:224
Security audit
Security checks across malware telemetry and agentic risk
LDM OS appears purpose-built for shared AI memory and tooling, but it installs broad persistent agent hooks and credential/profile behavior that users should review before installing.
Review this as infrastructure, not a simple prompt skill. Before installing, check the dry run and be comfortable with persistent Claude hooks, MCP registration, global npm installation, cron/process-monitor behavior, broad local backups, and the shell-profile export of a 1Password service-account token if present. Install only on a machine where you want LDM OS to manage multiple AI harnesses and shared local memory.
SkillSpector could not complete.
64/64 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command, suspicious.env_credential_access (+3 more)