← back to ckm-brand

Skill Scanner · ckm-brand

independent scanner by Cisco AI Defense · skill by Auto-Skiller · how it works ↗

FAILmax severity: CRITICAL

Skill name does not follow agent skills naming rules; Skill does not specify a license; Node.js filesystem access that could read or write sensitive data; +1 more

scanned 2026-08-22

Findings (10)

INFOpolicy_violation

Skill name does not follow agent skills naming rules

SKILL.md

INFOpolicy_violation

Skill does not specify a license

SKILL.md

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\extract-colors.cjs:47

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\inject-brand-context.cjs:328

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

scripts\sync-brand-to-tokens.cjs:14

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:219

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:232

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:246

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

scripts\sync-brand-to-tokens.cjs:253

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\validate-asset.cjs:195

What the verdicts mean

Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.

PASS

Reported as safe — no findings

CAUTION

Findings up to MEDIUM severity

WARNING

Findings of HIGH severity

FAILthis skill

Findings of CRITICAL severity

INCONCLUSIVE

Scan could not complete