← back to uupm-brand

Skill Scanner · uupm-brand

independent scanner by Cisco AI Defense · skill by oimiragieo · how it works ↗

FAILmax severity: CRITICAL

Skill does not specify a license; Node.js filesystem access that could read or write sensitive data; Node.js child_process module usage for shell command execution

scanned 2026-08-22

Findings (8)

INFOpolicy_violation

Skill does not specify a license

SKILL.md

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\extract-colors.cjs:47

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\inject-brand-context.cjs:328

CRITICALcommand_injection

Node.js child_process module usage for shell command execution

scripts\sync-brand-to-tokens.cjs:14

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:201

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:214

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\sync-brand-to-tokens.cjs:228

HIGHdata_exfiltration

Node.js filesystem access that could read or write sensitive data

scripts\validate-asset.cjs:195

What the verdicts mean

Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.

PASS

Reported as safe — no findings

CAUTION

Findings up to MEDIUM severity

WARNING

Findings of HIGH severity

FAILthis skill

Findings of CRITICAL severity

INCONCLUSIVE

Scan could not complete