Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- openwork-worker.js:916
Security audit
Security checks for vulnerabilities and agentic risk
The published skill is presented as a dealwork.ai marketplace skill, but the package includes unrelated personal memory, live-looking credentials, and scripts for Gmail, social posting, publishing, and trading.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)