issue-reporter — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited issue-reporter (Agent Skill) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 1 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 1 flagged
A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.
*.sig, SIGNATURES) outside the documentation.Every scanned point with the score it earned and what moved between them.
Aggregate score unchanged between these scans.
The primary manifest — the file an agent reads to learn what this artifact does.
每次提交前: gh auth status 2>&1。成功→GitHub模式,失败→本地模式。
Bug Report: 收集信息(描述/复现步骤/期望/平台/版本) → 查重 gh search issues "[关键词]" --repo CherryHQ/cherry-studio --state open --limit 5 → 读模板 .github/ISSUE_TEMPLATE/0_bug_report.yml → 预览给用户 → 确认后 gh issue create → 告知链接
Feature Request: 确认需求→查重→读模板 1_feature_request.yml→预览→确认→提交→记录到 .cherry-assistant/feature-requests.md
Bug 存 .cherry-assistant/bug-reports.md,Feature 存 feature-requests.md:
### [Bug/Feature]: [标题]
- **日期**: YYYY-MM-DD | **平台**: OS | **版本**: vX.X.X
- **描述**: ... | **复现步骤**: 1... 2... | **期望**: ...
- **状态**: 待提交
---存档后引导: GitHub(推荐) https://github.com/CherryHQ/cherry-studio/issues | 论坛 linux.do | 飞书表单
批量提交: 有权限时可说「帮我把待提交的都提交了」→读文件→筛待提交→逐个查重预览确认→更新状态为「已提交 #号」
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.