Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,5 @@
[![MseeP.ai Security Assessment Badge](https://mseep.net/pr/canner-wrenai-badge.png)](https://mseep.ai/app/canner-wrenai)
Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

⚠️ Potential issue | 🔴 Critical

This appears to be unsolicited third-party self-promotion and should not be merged.

This PR adds a badge from MseeP.ai—a service that appears to be promoting itself by submitting badge additions to open-source projects. Several critical concerns:

  1. Unsolicited promotion: The PR author is from MseeP.ai itself, not from the WrenAI maintainers. This is self-promotion by a third party without prior discussion or approval from the repository owners.

  2. External image hosting: The badge image is hosted on mseep.net, creating a dependency on an external service. MseeP.ai could change the image, track viewers, or the service could go offline. Best practice is to host badge images within the repository or use well-established, trusted badge services.

  3. Unverified claims: The badge claims to provide "security assessment," but there's no way to verify the legitimacy, methodology, or value of MseeP.ai's assessments. Adding this badge implies endorsement of their service.

  4. Inappropriate placement: The badge is positioned at the very top of the README, above even the project logo and title, giving undue prominence to a third-party commercial service.

  5. Privacy concerns: External image loading can be used for tracking and analytics on repository visitors.

  6. No community discussion: There's no prior issue or discussion about adding this badge, suggesting this is an unsolicited submission.

Recommendation: Decline this PR. If the WrenAI maintainers are interested in security badges, they should:

  • Evaluate security assessment services independently
  • Host badge images within the repository
  • Place badges in appropriate sections (typically with other status badges, not at the top)
  • Initiate the addition themselves after verification
🤖 Prompt for AI Agents
Verify each finding against the current code and only fix it if needed.

In `@README.md` at line 1, Remove the unsolicited MseeP.ai badge markdown line
(the string "[![MseeP.ai Security Assessment
Badge](https://mseep.net/pr/canner-wrenai-badge.png)](https://mseep.ai/app/canner-wrenai)")
from the README; do not add third‑party badges without maintainer approval, and
if a security badge is later accepted, host the image inside the repo or use a
trusted badge service and place it alongside other status badges (not at the
top).



<p align="center" id="top">
<a href="https://getwren.ai/?utm_source=github&utm_medium=title&utm_campaign=readme">
Expand Down