Skip to content

Add SafeSkill security badge (20/100 — Blocked)#50

Open
OyaAIProd wants to merge 1 commit intobookedsolidtech:mainfrom
OyaAIProd:safeskill-scan-1776737237411
Open

Add SafeSkill security badge (20/100 — Blocked)#50
OyaAIProd wants to merge 1 commit intobookedsolidtech:mainfrom
OyaAIProd:safeskill-scan-1776737237411

Conversation

@OyaAIProd
Copy link
Copy Markdown

🔴 SafeSkill Security Scan Results

Metric Value
Overall Score 20/100 (Blocked)
Code Score 64/100
Content Score 69/100
Findings 1631 findings detected (155 critical)
Taint Flows 63
Files Scanned 131
Scan Duration 16.4s

Note: This package is a CLI toolchild_process, filesystem, and environment access are expected capabilities and are excluded from scoring and top findings.

Top Findings

  • 🔴 critical: Detected instruction-override attempt: "ignore previous instructions" (src/gateway/middleware/injection.ts:12:12)
  • 🔴 critical: Detected instruction-override attempt: "your new instructions are" (src/gateway/middleware/injection.ts:12:14)
  • 🔴 critical: Detected instruction-override attempt: "you are now" (src/gateway/middleware/injection.ts:12:17)
  • 🔴 critical: Detected instruction-override attempt: "you are now" (src/gateway/middleware/injection.ts:12:17)
  • 🔴 critical: Detected instruction-override attempt: "you are now" (src/gateway/middleware/injection.ts:12:18)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

Signed-off-by: SafeSkill Scanner <mk@oya.ai>
@OyaAIProd OyaAIProd requested a review from himerus as a code owner April 21, 2026 02:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant