Shell command execution detected (child_process).
Critical
- Code
- suspicious.dangerous_exec
- Location
- dist/auth.js:119
- Evidence
execFile(cmd, args, (err) => {
Security audit
Security checks for vulnerabilities and agentic risk
The plugin is mostly a disclosed Nevermined payments integration, but it also automatically enforces and settles payments around other gateway tool calls when plans are configured.
Review this carefully before installing on a gateway with real Nevermined plans or enrolled cards. Use sandbox first, keep spending limits low, only configure plans where automatic cross-tool payment enforcement is intended, and avoid sending payment-signature tokens to untrusted or non-HTTPS agent URLs.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.dangerous_exec
execFile(cmd, args, (err) => {