Skip to content

Add SafeSkill security badge (20/100 — Blocked)#359

Open
OyaAIProd wants to merge 1 commit intoaaronsb:mainfrom
OyaAIProd:safeskill-scan-1775095666798
Open

Add SafeSkill security badge (20/100 — Blocked)#359
OyaAIProd wants to merge 1 commit intoaaronsb:mainfrom
OyaAIProd:safeskill-scan-1775095666798

Conversation

@OyaAIProd
Copy link
Copy Markdown

🔴 SafeSkill Security Scan Results

Metric Value
Overall Score 20/100 (Blocked)
Code Score 39/100
Content Score 29/100
Findings 728 findings detected (49 critical)
Taint Flows 49
Files Scanned 165
Scan Duration 21.0s

Top Findings

  • 🔴 critical: Imports child_process module (cli/scripts/check-docs.js:11)
  • 🔴 critical: Spawns child process (cli/scripts/check-docs.js:43)
  • 🔴 critical: Spawns child process (cli/scripts/check-docs.js:50)
  • 🔴 critical: Uses eval() (cli/scripts/generate-mcp-docs.mjs:149)
  • 🔴 critical: Imports child_process module (cli/scripts/generate-version.js:6)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant