critical
suspicious.dangerous_exec
- Location
- scripts/install-sidecar.mjs:50
- Finding
- Shell command execution detected (child_process).
- Evidence
const result = spawnSync(command, args, {
AdvisoryAudited by Static analysis on May 17, 2026.
Detected: suspicious.dangerous_exec, suspicious.install_untrusted_source
const result = spawnSync(command, args, {const child = spawn(python, [
"default": "http://127.0.0.1:8765",