Skip to content

Noticed some potential security flags in your repo #22

Description

@joshua-trustabl

Was checking out your repo and ran it through Trustabl. A couple of things seemed worth mentioning, the scan found 55 findings (6 critical, 6 high, 13 medium, 30 low). Not sure if you were aware, but a few patterns that stood out were Skill auto-approves unrestricted shell and Bundled skill script reads credentials or secrets. Might be intentional, just thought you'd want to know.


Add Trustabl to your CI — trustabl/trustabl-action:

- name: Trustabl scan
  uses: trustabl/trustabl-action@v1

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions