gitsafehub
github.com/sediman-agent/OpenSkynet ↗

sediman-agent/OpenSkynet

scanned 2026-07-25 · git c9d8953
2 of 6 checks flagged a security issue
🔴 Needs attention
Only 3 of 6 checks finished — treat this as provisional. Re-check ↻

Informational scan, not a security audit. How this is computed.

Leaked secretsVulnerable dependencies63Known OSS vulnerabilities172Risky code patternsMalicious dependenciesProject health

Security checks

Leaked secrets — Gitleaks timed out

API keys, passwords or tokens committed into the repo.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Gitleaks v8.21.2 · MIT

error: timeout after 400s

Vulnerable dependencies — Trivy 63 found · 2 serious

Packages you depend on that have known security holes (CVEs).

  • Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious CVE-2026-59873 tar: node-tar: Denial of Service via crafted gzip bomb
    package-lock.json
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54285 @opentelemetry/core: opentelemetry-js: @opentelemetry/core: Denial of Service via oversized baggage HTTP headers
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54285). Fix: Update that package to its patched version.
  • Worth fixing GHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
    bun.lock
    A package you depend on has a known security hole (GHSA-gcfj-64vw-6mp9). Fix: Update that package to its patched version.
  • Worth fixing GHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of service
    bun.lock
    A package you depend on has a known security hole (GHSA-42h9-826w-cgv3). Fix: Update that package to its patched version.
  • Worth fixing GHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype values
    bun.lock
    A package you depend on has a known security hole (GHSA-7q8q-rj6j-mhjq). Fix: Update that package to its patched version.
  • Worth fixing GHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
    bun.lock
    A package you depend on has a known security hole (GHSA-f4gw-2p7v-4548). Fix: Update that package to its patched version.
  • Worth fixing GHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatoken
    bun.lock
    A package you depend on has a known security hole (GHSA-hcpx-6fm6-wx23). Fix: Update that package to its patched version.
  • Worth fixing GHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
    bun.lock
    A package you depend on has a known security hole (GHSA-jqh4-m9w3-8hp9). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request construction
    bun.lock
    A package you depend on has a known security hole (GHSA-mmx7-hfxf-jppx). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
    bun.lock
    A package you depend on has a known security hole (GHSA-mwf2-3pr3-8698). Fix: Update that package to its patched version.
  • Worth fixing GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
    bun.lock
    A package you depend on has a known security hole (GHSA-pmv8-rq9r-6j72). Fix: Update that package to its patched version.
  • Worth fixing GHSA-xj6q-8x83-jv6g Axios: Prototype pollution auth subfields can inject Basic auth
    bun.lock
    A package you depend on has a known security hole (GHSA-xj6q-8x83-jv6g). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-12143 form-data: form-data: Form field override via CRLF injection
    bun.lock
    A package you depend on has a known security hole (CVE-2026-12143). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54290 hono: CORS Middleware reflects any Origin with credentials when `origin` defaults to the wildcard
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54290). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54286 hono: Path traversal in `serve-static` on Windows via encoded backslash (`%5C`)
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54286). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54287 hono: AWS Lambda adapter merges multiple `Set-Cookie` headers into one value, dropping cookies on ALB single-header and Lattice
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54287). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54288 hono: Body Limit Middleware can be bypassed on AWS Lambda by understating `Content-Length`
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54288). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-54289 hono: Lambda@Edge adapter keeps only the last value of a repeated request header, dropping the rest
    bun.lock
    A package you depend on has a known security hole (CVE-2026-54289). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59895 Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59895). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59896 hono/jsx does not isolate context per request, leading to cross-request data disclosure
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59896). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59897 Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-duplication
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59897). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59869 js-yaml: js-yaml: Denial of Service via crafted YAML documents
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59869). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59874 tar: Node-tar: Denial of Service via malformed tar archive header
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59874). Fix: Update that package to its patched version.
  • Worth fixing CVE-2026-59871 node-tar: node-tar: Denial of Service due to incorrect PAX path handling
    bun.lock
    A package you depend on has a known security hole (CVE-2026-59871). Fix: Update that package to its patched version.
… 38 more not shown

via Trivy v0.70.0 · Apache-2.0

Known OSS vulnerabilities — OSV-Scanner 172 found · 5 serious

Your dependencies cross-checked against the OSV vulnerability database.

  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/package-lock.json
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious GHSA-23hp-3jrh-7fpw node-tar: Decompression/parse DoS via unlimited input
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/package-lock.json
    A package you depend on has a known security hole (CVE-2026-59873). Fix: Update that package to its patched version.
  • Serious PYSEC-2026-457 Arbitrary Code Execution in Pillow
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/skills/anthropics_skills/slack-gif-creator/requirements.txt
    A package you depend on has a known security hole (CVE-2023-50447). Fix: Update that package to its patched version.
  • Worth fixing GHSA-8988-4f7v-96qf OpenTelemetry Core: Unbounded memory allocation in W3C Baggage propagation
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-54285). Fix: Update that package to its patched version.
  • Worth fixing GHSA-42h9-826w-cgv3 Axios: Excessive recursion in formDataToJSON can cause denial of service
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-7q8q-rj6j-mhjq Axios: Nested axios option objects can consume polluted prototype values
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-f4gw-2p7v-4548 Axios: NO_PROXY bypass for 0.0.0.0 local addresses in axios
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-gcfj-64vw-6mp9 Axios Node HTTP adapter can use an inherited proxy after interceptor config cloning
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-hcpx-6fm6-wx23 Axios form serializer maxDepth bypass via {} metatoken
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-jqh4-m9w3-8hp9 Axios: Fetch adapter `ReadableStream` uploads bypass `maxBodyLength`
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-mmx7-hfxf-jppx Axios: Prototype pollution gadgets can alter axios request construction
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-mwf2-3pr3-8698 Axios: HTTP/2 streamed uploads bypass `maxBodyLength`
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-pmv8-rq9r-6j72 Axios: Deep formToJSON Key Recursion Can Cause Denial of Service
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-xj6q-8x83-jv6g Axios: Prototype pollution auth subfields can inject Basic auth
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole. Fix: Update that package to its patched version.
  • Worth fixing GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-13149). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3jxr-9vmj-r5cp brace-expansion: DoS via exponential-time expansion of consecutive non-expanding {} groups
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-13149). Fix: Update that package to its patched version.
  • Worth fixing GHSA-mh99-v99m-4gvg brace-expansion: DoS via unbounded expansion length causing an out-of-memory process crash
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-14257). Fix: Update that package to its patched version.
  • Worth fixing GHSA-3c8v-cfp5-9885 Electron: Out-of-bounds read in second-instance IPC on macOS and Linux
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-34776). Fix: Update that package to its patched version.
  • Worth fixing GHSA-4p4r-m79c-wq3v Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-34767). Fix: Update that package to its patched version.
  • Worth fixing GHSA-532v-xpq5-8h95 Electron: Use-after-free in offscreen child window paint callback
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-34774). Fix: Update that package to its patched version.
  • Worth fixing GHSA-5rqw-r77c-jp79 Electron: AppleScript injection in app.moveToApplicationsFolder on macOS
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2026-34779). Fix: Update that package to its patched version.
  • Worth fixing GHSA-6r2x-8pq8-9489 Electron vulnerable to Heap Buffer Overflow in NativeImage
    /workdirs/scan-f739c0fb-0b2b-45a8-a04e-cce38308f33f/bun.lock
    A package you depend on has a known security hole (CVE-2024-46993). Fix: Update that package to its patched version.
… 147 more not shown

via OSV-Scanner v1.9.2 · Apache-2.0

Risky code patterns — Semgrep none found ✓

Code that can be exploited: injection, hardcoded credentials and similar.

Nothing found by this check. ✓

via Semgrep v1.147.0 · LGPL-2.1

Malicious dependencies — Guarddog timed out

Packages that look intentionally malicious: typosquats, sneaky install scripts.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via Guarddog v2.10.0 · Apache-2.0

error: npm:timeout

Project health

A signal about how the project is maintained — not a vulnerability in your code. It doesn’t affect the verdict above.

Project health — OpenSSF Scorecard didn’t run

Maintenance & supply-chain hygiene. A signal about the project, not a vulnerability in your code.

This check didn’t finish — that’s not the same as “clean.” Try Check again above.

via OpenSSF Scorecard · Apache-2.0

About these results. Six open-source checks ran in parallel; every finding is tagged with the tool that produced it. The verdict follows a published rule. False positives and false negatives are normal — a clean scan does not mean the code is secure, and a red verdict does not mean the project is compromised.