Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- scripts/piccc.mjs:640
Security audit
Security checks across malware telemetry and agentic risk
This skill connects to Piccc AI to generate and download media, with disclosed account authorization and local credential storage.
Install this if you intend to let your agent use your Piccc AI account and credits for media generation. Review generated-task costs, authorize only in the browser flow you expect, and use logout if you want to remove the saved local API key.
65/65 vendors flagged this skill as clean.
Detected: suspicious.dangerous_exec, suspicious.env_credential_access, suspicious.exposed_secret_literal (+1 more)