Skip to content

Add SafeSkill security badge (84/100 β€” Passes with Notes)#1

Open
OyaAIProd wants to merge 2 commits intoGabrielCostaLopes16:mainfrom
OyaAIProd:safeskill-scan-1774784218371
Open

Add SafeSkill security badge (84/100 β€” Passes with Notes)#1
OyaAIProd wants to merge 2 commits intoGabrielCostaLopes16:mainfrom
OyaAIProd:safeskill-scan-1774784218371

Conversation

@OyaAIProd
Copy link
Copy Markdown

⚠️ SafeSkill Security Scan Results

Metric Value
Overall Score 84/100 (Passes with Notes)
Code Score 85/100
Content Score 80/100
Findings 89 findings detected (21 critical)
Taint Flows 0
Files Scanned 8
Scan Duration 0.9s

Top Findings

  • πŸ”΄ critical: Imports child_process module (hook-scripts/post-tool-use/auto-stage.js:27)
  • πŸ”΄ critical: Spawns child process (hook-scripts/post-tool-use/auto-stage.js:42)
  • πŸ”΄ critical: Spawns child process (hook-scripts/post-tool-use/auto-stage.js:52)
  • πŸ”΄ critical: Makes HTTP request via fetch() (co-occurs with filesystem access β€” potential data exfiltration) (hook-scripts/notification/notify-permission.js:109)
  • πŸ”΄ critical: Requires child_process module "child_process" (hook-scripts/post-tool-use/auto-stage.js:27)

View full report on SafeSkill


This PR was automatically generated by SafeSkill β€” the security scanner for AI tools and MCP servers.

@GabrielCostaLopes16 GabrielCostaLopes16 force-pushed the main branch 28 times, most recently from dec6f66 to 7c8e3a2 Compare April 2, 2026 08:55
@GabrielCostaLopes16 GabrielCostaLopes16 force-pushed the main branch 4 times, most recently from f19c109 to 815f6cc Compare April 2, 2026 22:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants