Skip to content

Add SafeSkill security badge (91/100 — Verified Safe)#53

Open
OyaAIProd wants to merge 1 commit intozinja-coder:mainfrom
OyaAIProd:safeskill-scan-1774789702503
Open

Add SafeSkill security badge (91/100 — Verified Safe)#53
OyaAIProd wants to merge 1 commit intozinja-coder:mainfrom
OyaAIProd:safeskill-scan-1774789702503

Conversation

@OyaAIProd
Copy link
Copy Markdown

✅ SafeSkill Security Scan Results

Metric Value
Overall Score 91/100 (Verified Safe)
Code Score 99/100
Content Score 78/100
Findings 12 findings detected
Taint Flows 0
Files Scanned 0
Scan Duration 0.2s

Top Findings

  • 🟡 medium: Missing or invalid package.json (package.json:0)
  • 🟡 medium: Hidden/invisible text detected (variation-selector) at byte offset 8575: "U+FE0F" (README.md:204)
  • 🟡 medium: Hidden/invisible text detected (variation-selector) at byte offset 8841: "U+FE0F" (README.md:216)
  • 🟡 medium: Hidden/invisible text detected (variation-selector) at byte offset 9121: "U+FE0F" (README.md:226)
  • 🟡 medium: Hidden/invisible text detected (variation-selector) at byte offset 10251: "U+FE0F" (README.md:270)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

Copy link
Copy Markdown

@JiwaniZakir JiwaniZakir left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

The badge added in README.md links to https://safeskill.dev/scan/zinja-coder-jadx-mcp-server, but "SafeSkill" is not a recognized or established security auditing authority — there's no documentation in this PR explaining what criteria produced the 91/100 score, what was actually scanned, or who operates the service. Displaying a "Verified Safe" claim to users without verifiable methodology is potentially misleading, especially for a security-adjacent tool used in reverse engineering workflows where trust signals matter. This PR pattern — opening a one-line badge addition from an external, obscure service — is a common vector for SEO link-building campaigns targeting popular open source repos; the score and "verified" language are designed to incentivize acceptance. Before merging, the methodology, the organization behind safeskill.dev, and whether any actual security analysis was performed should be independently verified. If no credible audit trail exists, this badge should be rejected to avoid lending false credibility to users assessing whether to trust the tool.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants