External Script Fetching
- Category
- Supply Chain
- Confidence
- 15% confidence
- Finding
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- Content
md bins: - qwenpaw - python3 - curl env: [] ---
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed QwenPaw upgrade-check helper that reads version and release information without performing upgrades or persistent changes.
Install only if you are comfortable with a helper that runs qwenpaw --version, contacts PyPI and the QwenPaw release-notes site, and may inspect QwenPaw-related skills, plugins, or MCP settings to assess compatibility. It should not perform the upgrade automatically or request credentials.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
bins:
- qwenpaw
- python3
- curl
env: []
---
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
bins:
- qwenpaw
- python3
- curl
env: []
---
No suspicious patterns detected.