Skill Scanner · uupm-brand
independent scanner by Cisco AI Defense · skill by oimiragieo · how it works ↗
Skill does not specify a license; Node.js filesystem access that could read or write sensitive data; Node.js child_process module usage for shell command execution
scanned 2026-08-22
Findings (8)
Skill does not specify a license
SKILL.md
Node.js filesystem access that could read or write sensitive data
scripts\extract-colors.cjs:47
Node.js filesystem access that could read or write sensitive data
scripts\inject-brand-context.cjs:328
Node.js child_process module usage for shell command execution
scripts\sync-brand-to-tokens.cjs:14
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:201
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:214
Node.js filesystem access that could read or write sensitive data
scripts\sync-brand-to-tokens.cjs:228
Node.js filesystem access that could read or write sensitive data
scripts\validate-asset.cjs:195
What the verdicts mean
Skill Scanner reports on SkillMD's shared five-tier scale. See how Skill Scanner works ↗.
Reported as safe — no findings
Findings up to MEDIUM severity
Findings of HIGH severity
Findings of CRITICAL severity
Scan could not complete