Dangerous exec
Critical
- Finding
- Shell command execution detected (child_process).
- Skill content
execSync("npm run build", { cwd: root, stdio: "inherit", shell: true });
Security checks across static analysis, malware telemetry, and agentic risk
No artifact-backed suspicious behavior could be established from the available review context, but the local artifact files could not be inspected in this run.
Installers should still review the actual SKILL.md, metadata, and package contents before use, especially because this run could not inspect local artifact files directly.
execSync("npm run build", { cwd: root, stdio: "inherit", shell: true });child = execFile('openclaw', args, {rm -rf ~/.openclaw/plugins/gotoplan-manager
No VirusTotal findings
No visible risk-analysis findings were reported for this release.