Skip to content

Add SafeSkill security badge (46/100 — Use with Caution)#3170

Open
OyaAIProd wants to merge 1 commit intodecocms:mainfrom
OyaAIProd:safeskill-scan-1776996575501
Open

Add SafeSkill security badge (46/100 — Use with Caution)#3170
OyaAIProd wants to merge 1 commit intodecocms:mainfrom
OyaAIProd:safeskill-scan-1776996575501

Conversation

@OyaAIProd
Copy link
Copy Markdown

@OyaAIProd OyaAIProd commented Apr 24, 2026

🟠 SafeSkill Security Scan Results

Metric Value
Overall Score 46/100 (Use with Caution)
Code Score 35/100
Content Score 75/100
Findings 1074 findings detected (120 critical)
Taint Flows 79
Files Scanned 949
Scan Duration 47.0s

Top Findings

  • 🔴 critical: Imports child_process module (packages/create-deco/index.js:10)
  • 🔴 critical: Spawns child process (packages/create-deco/index.js:21)
  • 🔴 critical: Uses Function constructor (packages/mesh-plugin-user-sandbox/shared.ts:33)
  • 🔴 critical: Imports child_process module (packages/vite-plugin-deco/index.ts:4)
  • 🔴 critical: Spawns child process (packages/vite-plugin-deco/index.ts:26)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.


Summary by cubic

Add a SafeSkill security badge (46/100 — Use with Caution) to the README, linking to the live scan report. This makes the project’s current security status visible at a glance for contributors and users.

Written for commit fa4eb3b. Summary will update on new commits.

Signed-off-by: SafeSkill Scanner <mk@oya.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant