Skip to content

Add SafeSkill security badge (88/100 — Passes with Notes)#43

Closed
OyaAIProd wants to merge 1 commit into
devkindhq:mainfrom
OyaAIProd:safeskill-scan-1778810800047
Closed

Add SafeSkill security badge (88/100 — Passes with Notes)#43
OyaAIProd wants to merge 1 commit into
devkindhq:mainfrom
OyaAIProd:safeskill-scan-1778810800047

Conversation

@OyaAIProd

Copy link
Copy Markdown

⚠️ SafeSkill Security Scan Results

Metric Value
Overall Score 88/100 (Passes with Notes)
Code Score 88/100
Content Score 92/100
Findings 76 findings detected (14 high)
Taint Flows 2
Files Scanned 31
Scan Duration 8.9s

Note: This package is an MCP serverchild_process, filesystem, and environment access are expected capabilities for tool servers and are excluded from scoring and top findings.

Top Findings

  • 🟠 high: Has prepare script: "npm run build && node scripts/ensure-executable.js" (package.json:0)
  • 🟠 high: Dependency "@semantic-release/git" is suspiciously similar to popular package "got" (possible typosquatting) (package.json:0)
  • 🟡 medium: Makes HTTP request via fetch (src/utils/transport.util.ts:58)
  • 🟡 medium: Makes HTTP request via fetch() (src/utils/transport.util.ts:58)
  • low: Contains external URL (src/utils/swell-config.util.ts:293)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

Signed-off-by: SafeSkill Scanner <mk@oya.ai>
@rome2o rome2o closed this May 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants