You'll presumably be executing the code which could trivially include `childProcess.spawn()`. I think energy would be better spent vetting the author of the package. If you're concerned, install it in a VM. It's never safe to run code in any language if you think it might be suspect.