Dangerous exec
Critical
- Finding
- Shell command execution detected (child_process).
- Skill content
return spawn(invocation.command, invocation.args, {
Security checks across static analysis, malware telemetry, and agentic risk
No risk analysis has been recorded yet.
return spawn(invocation.command, invocation.args, {const child = spawn(invocation.command, invocation.args, {const authToken = [REDACTED](config.authToken);
apiKey: [REDACTED],
apiKey: [REDACTED],
apiKey: [REDACTED],
const authToken = [REDACTED] ?? "";
const apiKey = [REDACTED](resolveCodexAppServerSpawnEnv(params.startOptions, params.baseEnv ?? process.env, params.platform ?? process.platform), CODEX_APP_SERV...
62/62 vendors flagged this plugin as clean.
No visible risk-analysis findings were reported for this release.