Skip to content

Add SafeSkill security badge (50/100 — Use with Caution)#1

Open
OyaAIProd wants to merge 1 commit into
ApocData:mainfrom
OyaAIProd:safeskill-scan-1779761201048
Open

Add SafeSkill security badge (50/100 — Use with Caution)#1
OyaAIProd wants to merge 1 commit into
ApocData:mainfrom
OyaAIProd:safeskill-scan-1779761201048

Conversation

@OyaAIProd

Copy link
Copy Markdown

🟠 SafeSkill Security Scan Results

Metric Value
Overall Score 50/100 (Use with Caution)
Code Score 50/100
Content Score 70/100
Findings 58 findings detected (32 high)
Taint Flows 0
Files Scanned 0
Scan Duration 0.1s

Top Findings

  • 🟠 high: Hidden/invisible text detected (homoglyph) at byte offset 92: "Word "pip)" contains non-ASCII lookalikes: U+FF09" (SKILL.md:5)
  • 🟠 high: Hidden/invisible text detected (homoglyph) at byte offset 308: "Word "GET," contains non-ASCII lookalikes: U+FF0C" (SKILL.md:19)
  • 🟠 high: Hidden/invisible text detected (homoglyph) at byte offset 927: "Word "K," contains non-ASCII lookalikes: U+FF0C" (SKILL.md:63)
  • 🟠 high: Hidden/invisible text detected (homoglyph) at byte offset 1018: "Word "(start" contains non-ASCII lookalikes: U+FF08" (SKILL.md:68)
  • 🟠 high: Hidden/invisible text detected (homoglyph) at byte offset 1031: "Word "YYYYMMDD," contains non-ASCII lookalikes: U+FF0C" (SKILL.md:68)

View full report on SafeSkill


About SafeSkill

SafeSkill is a free, open-source security scanner for AI tools, MCP servers, and Claude Code skills. We scan for code exploits, prompt injection, and data exfiltration risks.

False positive? We take accuracy seriously. If any finding above is incorrect, please open an issue and we will fix it immediately.

Signed-off-by: SafeSkill Scanner <mk@oya.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant