← back to uupm-brand

SkillSpector · uupm-brand

independent scanner by NVIDIA · skill by oimiragieo · how it works ↗

CAUTIONmax severity: MEDIUMrisk score: 37

subprocess module calls execute external commands. Without careful input validation, this enables command injection.; Without declared permissions the skill's intent is opaque and cannot be validated.; Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

scanned 2026-08-23

Findings (3)

MEDIUMDangerous Code Executionconfidence: 0.7

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

scripts/tests/test_sync_brand_to_tokens.py

MEDIUMMCP Least Privilegeconfidence: 0.7

Without declared permissions the skill's intent is opaque and cannot be validated.

SKILL.md

HIGHSystem Prompt Leakageconfidence: 0.85

Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.

scripts/inject-brand-context.cjs

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTIONthis skill

Overall severity MEDIUM

WARNING

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete