Shell command execution detected (child_process).
- Code
- suspicious.dangerous_exec
- Location
- index.js:214
Security audit
Security checks across malware telemetry and agentic risk
This is a powerful self-modifying, networked agent-evolution skill that is mostly purpose-aligned but has high-impact automatic execution, persistence, data-sharing, and provenance concerns that need review before use.
Install only if you intentionally want an autonomous self-evolution tool. Use a disposable or well-versioned git workspace, run `--review` instead of automated mode, avoid `--loop` until supervised, do not provide GitHub or remote-memory credentials unless necessary, and verify the package provenance because the registry and embedded metadata do not match.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)