Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- openwork-worker.js:916
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a Dealwork marketplace skill, but the package includes unrelated automations, exposed credentials, durable memory, and persistent background behavior that are not adequately scoped.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)