Skip to content

Add SafeSkill security badge (86/100 — Passes with Notes)#1

Open
OyaAIProd wants to merge 1 commit intokalpeshgamit:mainfrom
OyaAIProd:safeskill-scan-1775527622336
Open

Add SafeSkill security badge (86/100 — Passes with Notes)#1
OyaAIProd wants to merge 1 commit intokalpeshgamit:mainfrom
OyaAIProd:safeskill-scan-1775527622336

Conversation

@OyaAIProd
Copy link
Copy Markdown

⚠️ SafeSkill Security Scan Results

Metric Value
Overall Score 86/100 (Passes with Notes)
Code Score 90/100
Content Score 86/100
Findings 507 findings detected (14 critical)
Taint Flows 2
Files Scanned 79
Scan Duration 5.2s

Top Findings

  • 🔴 critical: Imports child_process module (src/cli/ui.ts:5)
  • 🔴 critical: Spawns child process (src/cli/ui.ts:151)
  • 🔴 critical: Spawns child process (src/intelligence/imports.ts:94)
  • 🔴 critical: Spawns child process (src/intelligence/search.ts:45)
  • 🔴 critical: Spawns child process (src/intelligence/search.ts:54)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

@kalpeshgamit
Copy link
Copy Markdown
Owner

Thanks! Badge added to the badge row at top of README (commit acad1e1). The 14 critical findings are expected — child_process for daemon and better-sqlite3 for search are core features. Closing since badge was added directly.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants