Skip to content

Add SafeSkill security badge (73/100 — Passes with Notes)#1

Open
OyaAIProd wants to merge 1 commit intobrowserkit-dev:mainfrom
OyaAIProd:safeskill-scan-1774780248945
Open

Add SafeSkill security badge (73/100 — Passes with Notes)#1
OyaAIProd wants to merge 1 commit intobrowserkit-dev:mainfrom
OyaAIProd:safeskill-scan-1774780248945

Conversation

@OyaAIProd
Copy link
Copy Markdown

⚠️ SafeSkill Security Scan Results

Metric Value
Overall Score 73/100 (Passes with Notes)
Code Score 65/100
Content Score 84/100
Findings 149 findings detected (5 critical)
Taint Flows 2
Files Scanned 26
Scan Duration 1.5s

Top Findings

  • 🔴 critical: Network call: http.request() (co-occurs with filesystem access — potential data exfiltration) (packages/core/src/cli.ts:216)
  • 🔴 critical: Network call: http.get() (co-occurs with filesystem access — potential data exfiltration) (packages/core/src/cli.ts:255)
  • 🔴 critical: Network call: net.createServer() (co-occurs with filesystem access — potential data exfiltration) (packages/core/src/testing/test-server.ts:57)
  • 🔴 critical: Imports child_process module "node:child_process" (tests/e2e/smoke.test.ts:24)
  • 🔴 critical: Spawns child process: spawn() (tests/e2e/smoke.test.ts:67)

View full report on SafeSkill


This PR was automatically generated by SafeSkill — the security scanner for AI tools and MCP servers.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant