← back to cue-your-ai-research-assistant

Skill Scanner · cue-your-ai-research-assistant

independent scanner by Cisco AI Defense · skill by modbender · how it works ↗

FAILmax severity: CRITICAL

Skill name does not follow agent skills naming rules; Skill does not specify a license; Unicode homoglyph characters detected in code; +3 more

scanned 2026-08-22

Findings (20)

INFOpolicy_violation

Skill name does not follow agent skills naming rules

SKILL.md

INFOpolicy_violation

Skill does not specify a license

SKILL.md

HIGHobfuscation

Unicode homoglyph characters detected in code

backups\scripts-v1.0.3-20260226-015020\cue.sh:478

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

backups\scripts-v1.0.3-20260226-015020\cuecue-client.js:361

MEDIUMdata_exfiltration

Outbound network request primitives in JavaScript/TypeScript

src\api\cuecueClient.js:192

MEDIUMdata_exfiltration

Outbound network request primitives in JavaScript/TypeScript

src\api\cuecueClient.js:239

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\core\backgroundExecutor.js:6

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\core\logger.js:59

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\core\userState.js:44

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\core\userState.js:45

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\core\userState.js:61

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\core\userState.js:64

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\cron\monitor-daemon.js:11

MEDIUMdata_exfiltration

Outbound network request primitives in JavaScript/TypeScript

src\cron\monitor-daemon.js:109

MEDIUMdata_exfiltration

Outbound network request primitives in JavaScript/TypeScript

src\cron\monitor-daemon.js:131

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\cron\monitor-daemon.js:217

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\cron\monitor-daemon.js:228

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\notifier\index.js:6

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

src\notifier\index.js:64

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

src\utils\envUtils.js:41

What the verdicts mean

Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.

PASS

Reported as safe — no findings

CAUTION

Findings up to MEDIUM severity

WARNING

Findings of HIGH severity

FAILthis skill

Findings of CRITICAL severity

INCONCLUSIVE

Scan could not complete