← back to cue-your-ai-research-assistant
SkillSpector · cue-your-ai-research-assistant
independent scanner by NVIDIA · skill by modbender · how it works ↗
Without declared permissions the skill's intent is opaque and cannot be validated.; Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.; Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.; +6 more
scanned 2026-08-23
Findings (20)
Without declared permissions the skill's intent is opaque and cannot be validated.
SKILL.md
Mixing characters from multiple Unicode scripts in a single identifier is a common technique to create visually ambiguous tool names.
SKILL.md
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/integrated-search.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/integrated-search.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/integrated-search.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/integrated-search.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/search-executor.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
backups/scripts-v1.0.3-20260226-015020/executor/search-executor.sh
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
src/cron/monitor-daemon.js
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
src/cron/monitor-daemon.js
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
src/cron/monitor-daemon.js
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
src/cron/monitor-daemon.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/cli.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/index.js
Skill attempts to fill the context window with filler content, displacing legitimate instructions and safety constraints. This can degrade agent performance or bypass safety boundaries.
src/index.js
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete