← back to cue-your-ai-research-assistant
Skill Scanner · cue-your-ai-research-assistant
independent scanner by Cisco AI Defense · skill by modbender · how it works ↗
Skill name does not follow agent skills naming rules; Skill does not specify a license; Unicode homoglyph characters detected in code; +3 more
scanned 2026-08-22
Findings (20)
Skill name does not follow agent skills naming rules
SKILL.md
Skill does not specify a license
SKILL.md
Unicode homoglyph characters detected in code
backups\scripts-v1.0.3-20260226-015020\cue.sh:478
Node.js filesystem access that could read or write sensitive data
backups\scripts-v1.0.3-20260226-015020\cuecue-client.js:361
Outbound network request primitives in JavaScript/TypeScript
src\api\cuecueClient.js:192
Outbound network request primitives in JavaScript/TypeScript
src\api\cuecueClient.js:239
Node.js child_process module usage for shell command execution
src\core\backgroundExecutor.js:6
Node.js filesystem access that could read or write sensitive data
src\core\logger.js:59
Node.js filesystem access that could read or write sensitive data
src\core\userState.js:44
Node.js filesystem access that could read or write sensitive data
src\core\userState.js:45
Node.js filesystem access that could read or write sensitive data
src\core\userState.js:61
Node.js filesystem access that could read or write sensitive data
src\core\userState.js:64
Node.js child_process module usage for shell command execution
src\cron\monitor-daemon.js:11
Outbound network request primitives in JavaScript/TypeScript
src\cron\monitor-daemon.js:109
Outbound network request primitives in JavaScript/TypeScript
src\cron\monitor-daemon.js:131
Node.js child_process module usage for shell command execution
src\cron\monitor-daemon.js:217
Node.js child_process module usage for shell command execution
src\cron\monitor-daemon.js:228
Node.js child_process module usage for shell command execution
src\notifier\index.js:6
Node.js child_process module usage for shell command execution
src\notifier\index.js:64
Node.js filesystem access that could read or write sensitive data
src\utils\envUtils.js:41
What the verdicts mean
Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.
Reported as safe — no findings
Findings up to MEDIUM severity
Findings of HIGH severity
Findings of CRITICAL severity
Scan could not complete