Skill Scanner · ckm-brand
independent scanner by Cisco AI Defense · skill by Auto-Skiller · how it works ↗
Skill name does not follow agent skills naming rules; Skill does not specify a license; Node.js filesystem access that could read or write sensitive data; +1 more
scanned 2026-08-22
Findings (10)
Skill name does not follow agent skills naming rules
SKILL.md
Skill does not specify a license
SKILL.md
Node.js filesystem access that could read or write sensitive data
scripts\extract-colors.cjs:47
Node.js filesystem access that could read or write sensitive data
scripts\inject-brand-context.cjs:328
Node.js child_process module usage for shell command execution
scripts\sync-brand-to-tokens.cjs:14
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:219
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:232
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:246
Node.js child_process module usage for shell command execution
scripts\sync-brand-to-tokens.cjs:253
Node.js filesystem access that could read or write sensitive data
scripts\validate-asset.cjs:195
What the verdicts mean
Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.
Reported as safe — no findings
Findings up to MEDIUM severity
Findings of HIGH severity
Findings of CRITICAL severity
Scan could not complete