Knap Markdown Templates
kepano/obsidian-skills
Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.
Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .claude/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .claude/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scanType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .agents/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .agents/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .cursor/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .cursor/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/logseq/logseq.git --path .agents/skills/esm-cjs-risk-scan--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .gemini/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .gemini/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install logseq/logseq esm-cjs-risk-scanInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .github/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .github/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add logseq/logseq --skill esm-cjs-risk-scan -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install logseq/logseq esm-cjs-risk-scan --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/logseq/logseq.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/esm-cjs-risk-scan .opencode/skills/esm-cjs-risk-scan && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "esm-cjs-risk-scan" agent skill from https://github.com/logseq/logseq/tree/master/.agents/skills/esm-cjs-risk-scan into .opencode/skills/esm-cjs-risk-scan/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "esm-cjs-risk-scan", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
esm-cjs-risk-scanScan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.
Esm Cjs Risk Scan is an agent skill from logseq/logseq. Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims. Use when changing Electron/main-process dependencies, debugging startup import errors, or auditing packages before dependency upgrades.
Its SKILL.md is about 3.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in Knowledge Management, covering CSV and tabular files. It works with npm. The repository describes itself as: A privacy-first, open-source platform for knowledge management and collaboration. Download link: http://github.com/logseq/logseq/releases. roadmap: https://logseq.io/p/NX4mcggEV. The licence is AGPL-3.0.
6 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 22a29b3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodepnpmFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pnpm, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Esm Cjs Risk Scan loads about 3.3k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 1,381 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from logseq/logseq at commit 22a29b3, republished under its AGPL-3.0 licence (© logseq). 1,381 words, ~3,261 tokens.
.claude/skills/esm-cjs-risk-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Scan Node/Electron ClojureScript code for npm dependencies that may fail at runtime due to ESM/CJS incompatibility. Use when changing Electron dependencies, debugging startup import errors, or auditing before dependency upgrades.
# Default scan (electron scope, human-readable table)
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs
# Scan all Node targets
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --scope all-node
# Machine-readable TSV output
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --format tsv
# JSON output
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --format json
# Show full error details in probe results
node .agents/skills/esm-cjs-risk-scan/scripts/scan_esm_cjs_risk.mjs --verbose| Parameter | Values | Default | Description |
|---|---|---|---|
--scope | electron, all-node | electron | Which source directories and package locations to scan |
--format | table, tsv, json | table | Output format. table is grouped and human-readable; tsv is tab-separated for machine parsing; json for programmatic use |
--verbose / -v | (flag) | off | Show full error messages in probe results instead of abbreviated ERR |
| Scope | Source Directories | Description |
|---|---|---|
electron | src/electron/electron | Electron main-process code only |
all-node | See table below | All Node/server-side code across the repo |
all-node source directories and their basis:
| Directory | Build target / role |
|---|---|
src/electron/electron | :electron target — :node-script (Electron main process) |
src/test | :test / :test-no-worker — :node-test (test runner) |
deps/cli/src | CLI tool (nbb Node script, uses fs-extra, path) |
deps/db-sync/src, deps/db-sync/test | DB sync server / Node adapter |
deps/db/script, deps/db/test | DB utility scripts |
deps/graph-parser/src, test, script | Graph parser CLI and tests |
deps/publishing/script, test | Publishing CLI and tests |
Browser/Worker builds (:app, :db-worker, :inference-worker, :mobile) are intentionally excluded — their npm deps are resolved at bundle time and never require()-called directly in Node.
The scanner detects three import patterns in .cljs / .cljc / .clj files:
| Pattern | Kind | Example |
|---|---|---|
["pkg" :as x] | npm-import | ["electron" :as e] — shadow-cljs npm import (compiled to require() for Node targets) |
js/require "pkg" | js-require | (js/require "update-electron-app") — Direct runtime require() call |
dynamic-import "pkg" | dynamic-import | (shadow.esm/dynamic-import "https-proxy-agent") — Async ESM import() |
| Risk | Meaning | Action |
|---|---|---|
| HIGH | Package cannot be loaded by any mechanism. js-require with all probes failing; dynamic-import with import probe failing; or npm-import where both require() and import() fail (esm-? mode) | Must replace the package — no loading workaround exists |
| MEDIUM | npm-import where require() fails but import() works (esm-imp mode). Caused by packages whose exports map has only "import" conditionals with no "require" or top-level "default" fallback — Node's module resolver rejects require(). shadow-cljs generates require() which will fail | Switch to dynamic-import |
| OK | Package loads successfully from at least one probe CWD, or is esm-req/esm-edep — safe to use in ns-form require | No action needed |
| INFO | Relative path requires or Node builtins; always safe | Informational only |
| Column | Description |
|---|---|
PACKAGE | npm package name as referenced in source code |
VER | Version from package.json (- if not installed) |
KIND | Import mechanism: npm-import, js-require, or dynamic-import |
TYPE | Package type field: cjs (CommonJS), esm (ESM type:module), blt (Node builtin), - (unset) |
MODE | Module load mode (see below). Abbreviated in table; full names in TSV/JSON |
REQUIRE | Simplified require() probe results per CWD (see Probe Results below) |
FILE | Source file containing the import |
HIGH/MEDIUM items additionally show: exports and import probe values.
| Mode (full) | Table abbrev | Meaning |
|---|---|---|
cjs-or-nonmodule | cjs | type is not module. CJS or unspecified — always works with require() |
module-require-compatible | esm-req | type: module but require() still works (Node 22+ or dual-mode package) |
module-electron-dep | esm-edep | type: module; probe fails only because Electron runtime (electron package) is absent. Works fine in actual Electron. |
module-import-only | esm-imp | type: module and only loadable via import(). require() will fail |
module-unloadable | esm-? | type: module and both require() and import() fail in current environment |
builtin | blt | Node.js built-in module (fs, path, os, child_process, etc.) |
Not merely "type": "module". Node 22+ supports require(esm) for ESM modules without top-level await. The real determiner is the exports map structure:
| Package exports structure | require() behavior | Example |
|---|---|---|
No exports field (only main) | ✅ Works in Node 22+ | node-fetch@3.3.2 |
exports has top-level "default" key | ✅ Works in Node 22+ | electron-dl@4.0.0 ({"types":…, "default":…}) |
exports has "require" key | ✅ Works (explicit CJS path) | Most dual-mode packages |
exports has only "import" key, no "default" | ❌ Rejected by Node's module resolver | https-proxy-agent ({"import":{…}}) |
The scanner's esmOnly flag (in TSV/JSON output) marks the last case — exports explicitly restricts to import-only. Classification always uses probe results as the authoritative source.
The scanner tests require() and import() from three CWD locations:
| Abbreviation | Directory | Role |
|---|---|---|
S | static/ | Primary Electron runtime directory |
R | resources/ | Secondary resources directory |
. | repository root | Development directory |
Compact display (default mode):
| Display | Meaning |
|---|---|
ALL:OK | Loads from all three CWDs |
ALL:ERR | Fails from all three CWDs |
ALL:ERR(e-dep) | All failures are electron-runtime errors; package loads fine in Electron |
S:OK R:ERR .:ERR | Loads from static/ only (normal for Electron packages) |
S:ERR(e-dep) R:ERR(e-dep) .:ERR | Probe fails because electron runtime is absent; package loads fine in Electron |
SKIP(electron) | Skipped for electron runtime package |
BUILTIN | Node.js built-in module |
Use --verbose (-v) for error details, e.g. S:OK R:ERR(MODULE_NOT_FOUND) .:ERR(MODULE_NOT_FOUND).
All fields tab-separated, one row per usage:
risk, kind, package, version, type, module_mode, exports_require, exports_import, require_probe, import_probe, file
Probe columns contain raw probe strings (e.g. static=OK;resources=ERR:MODULE_NOT_FOUND;.=ERR:MODULE_NOT_FOUND).
dynamic-import or CJS-compatible alternative.S:OK-only packages are expected (installed in static/node_modules only).pnpm exec electron static/electron.jsNo. This is normal for Electron-specific packages (e.g., keytar, update-electron-app, electron-window-state). They are installed in static/node_modules/ (the Electron app directory). The resources/ and root directories don't need them.
This error appears when probing packages that depend on electron at runtime (e.g., update-electron-app) from directories where electron isn't properly available. Not a real issue — the package works fine from static/ (S:OK), which is where Electron actually runs.
Detected automatically and shown with BUILTIN probe status. Always work in Node/Electron targets. Classified as OK.
electron-* package probingOnly the electron package itself (the runtime framework) skips probing. Other electron-* packages (electron-log, electron-window-state, electron-dl, etc.) are regular npm packages and are probed normally.
module-electron-dep modeSome ESM packages (e.g. electron-dl v4) internally call import { BrowserWindow } from 'electron'. When the scanner probes them with a plain Node.js require(), the call fails — not because the package is unloadable, but because the electron npm package (an installer shim) doesn't expose Electron's named runtime exports.
In the actual Electron runtime, the electron module IS the framework, so BrowserWindow and friends resolve correctly. The generated shadow.js shim (shadow.js.nativeProvides["electron-dl"] = require("electron-dl")) works fine at Electron startup.
How the scanner detects this: If every probe failure contains 'electron' in the error message (the named-export failure pattern), the package is reclassified from module-unloadable → module-electron-dep and from MEDIUM/HIGH → OK. Probe column shows ERR(e-dep) to mark the probe location.
When to verify manually: If a new package shows esm-edep unexpectedly, inspect its source — it should contain import ... from 'electron' or use Electron APIs directly. You can also check the compiled Electron shim cache at .shadow-cljs/builds/electron/dev/goog-js/ (Transit JSON, dev build) or .shadow-cljs/builds/electron/release/closure-inputs/ (plain JS, release build) for shadow.js.shim.module$<package>.js files — their content will show require("pkg") if shadow-cljs successfully resolved the package for the Node/Electron target.
The scanner runs require() and import() probes in a plain Node.js process (node -e ...), not inside a real Electron runtime. This means:
module-electron-dep heuristic to handle this case automaticallyimport ... from 'electron'), a manual check may be neededIf a build has already been compiled, you can inspect .shadow-cljs/builds/electron/release/closure-inputs/ for shadow.js.shim.module$<package>.js files (plain JS, immediately readable). The presence of require("pkg") in the shim content confirms shadow-cljs successfully resolved the package for the Electron Node target. This is the definitive ground truth; the scanner's probe is a pre-build approximation.
Note:
static/js/cljs-runtime/contains shims for browser worker targets that use:js-provider :external(currently:db-workerand:inference-worker). Those shims useshadow$bridge("pkg")— notrequire()— delegating actual module loading to the Webpack-bundled worker bundle. The:apptarget does not use:js-provider :externaland its missing modules throw"Module not provided"at runtime instead. Electron (:node-script) shims never appear in this directory either.
For HIGH risk:
(shadow.esm/dynamic-import "pkg") for ESM-only packagesFor MEDIUM risk:
(shadow.esm/dynamic-import "pkg")require(esm) covers your case (module-require-compatible mode)Re-run the scanner after changes to verify fixes.
© logseq, AGPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in .agents/skills/esm-cjs-risk-scan of logseq/logseq.
Open the folder on GitHubat commit 22a29b3
Esm Cjs Risk Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Esm Cjs Risk Scan this skilllogseq/logseq | 45k | — | ~3.3k | Automated safety check: Pass | AGPL-3.0 | |
| Knap Markdown Templateskepano/obsidian-skills | 49k | 2 repos | ~986 | Automated safety check: Pass | MIT | |
| Wellally Techhuifer/WellAlly-health | 960 | 5 repos | ~4.8k | Automated safety check: Pass | MIT | |
| Portaljs Add Datasetdatopian/portaljs | 2.4k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Download Statsnubjs/nub | 4.4k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Defuddlekepano/obsidian-skills | 49k | 11 repos | ~208 | Automated safety check: Pass | MIT |
kepano/obsidian-skills
Renders Markdown notes from Knap templates and JSON data on the command line, including notes built from Defuddle web page output.
huifer/WellAlly-health
Integrate digital health data sources (Apple Health, Fitbit, Oura Ring) and connect to WellAlly.tech knowledge base.
datopian/portaljs
Add a dataset (CSV, TSV, JSON, or GeoJSON) to an existing PortalJS portal.
nubjs/nub
Generate download-stats CSVs and a chart for nub across its distribution channels (npm + GitHub release assets, which subsume Homebrew).
kepano/obsidian-skills
Uses the Defuddle CLI to pull clean, readable Markdown, JSON or metadata from web pages, stripping navigation, ads and clutter to save tokens.
Tencent/teamai-cli
Make every team AI native — TeamAI syncs a team's AI skills, rules, docs and env across AI coding tools. Use when the task operates on team-shared AI…
logseq/logseq
Compare two revisions of the Logseq logseq-review-workflow skill by running the same review prompt against isolated before and after skill snapshots, collecting both outputs, and producing a…
logseq/logseq
Build, debug, or review Logseq plugins with the @logseq/libs SDK (TypeScript/JavaScript, iframe/shadow sandboxed).
logseq/logseq
Operate the current Logseq command-line interface to inspect or modify graphs, pages, blocks, tasks, tags, and properties; run Datascript queries; show page/block trees; manage graphs; and manage…
logseq/logseq
Audit, plan, and refresh dependency upgrades for the Logseq repository by scanning every non-gitignored package.json, deps.edn, bb.edn and nbb.edn manifest, checking latest upstream versions…
logseq/logseq
Logseq i18n workflow for adding, renaming, reviewing, or editing translation keys and user-facing strings.
logseq/logseq
Answer user questions about the Logseq repository by researching source code, docs, tests, runtime behavior, and local tools.
Works with
Categories
Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims. Esm Cjs Risk Scan is an agent skill from logseq/logseq. Scan Logseq ClojureScript Node/Electron targets for npm module loading risks, especially ESM-only packages that may fail when loaded through js/require or shadow-cljs require-based shims.
Esm Cjs Risk Scan fits situations like: changing Electron/main-process dependencies; debugging startup import errors; auditing packages before dependency upgrades.
Run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a claude-code`. Or copy the skill folder (.agents/skills/esm-cjs-risk-scan in logseq/logseq) into .claude/skills/esm-cjs-risk-scan in your project. Claude Code loads it when a task matches its description.
Run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a codex`. Or copy the skill folder (.agents/skills/esm-cjs-risk-scan in logseq/logseq) into .agents/skills/esm-cjs-risk-scan in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add logseq/logseq --skill esm-cjs-risk-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/esm-cjs-risk-scan, .gemini/skills/esm-cjs-risk-scan, .github/skills/esm-cjs-risk-scan and .opencode/skills/esm-cjs-risk-scan in your project.
Going by SKILL.md and its folder, Esm Cjs Risk Scan needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node and pnpm). Our summary lists: Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Esm Cjs Risk Scan is published under the AGPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.3k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Esm Cjs Risk Scan: Knap Markdown Templates (kepano/obsidian-skills, 49k stars), Wellally Tech (huifer/WellAlly-health, 960 stars), Portaljs Add Dataset (datopian/portaljs, 2.4k stars) and Download Stats (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
logseq (a GitHub organization) maintains it in logseq/logseq, which has 45,158 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 7, 2026.
Source: logseq/logseq on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.