chestnyznak-mcp— mcp server

MCP server for Chestniy ZNAK (Честный ЗНАК) API — product marking verification. No auth needed for

by theYahia·MCP Server·github.com/theYahia/chestnyznak-mcp

Is chestnyznak-mcp safe to install?

SaferSkills independently audited chestnyznak-mcp (MCP Server) and scored it 45/100 (orange). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 93 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.

Score
45/100
●●●●●○○○○○
↑ +0 since first scan (45 → 45)Re-scan~30s
Latest scan
ScannedJun 25, 2026 · 33d ago
Scans run1 over 90 days
Detectors55 checks · 5 categories
Findings0 warnings · 93 high
EngineSaferSkills 2b638c6
View methodology →
SaferSkills installs
This week0
This month0
All time0
CategoryWeightCategory scoreContribution
Securityprompt, exec, net, exfil, eval
35%
0
0.0 pts
Supply chainhash, typosquat, maintainer, lockfile
20%
100
20.0 pts
Maintenancestaleness, pinning, CI
15%
100
15.0 pts
TransparencySKILL.md, perms, README
15%
100
15.0 pts
Communityinstalls, verify, response
15%
100
15.0 pts

Findings & checks · 93 flagged

Securityscore 0 · 93 findings
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json×10
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json· json
136"url": "https://docs.crpt.ru/gismt/True_API/",
137"long_name": "docs.crpt.ru",
138"img": "https://imgs.search.brave.com/QUXZ7x8OdZyvrJ6oqtkWJGoWZ4lx4BpYjNZXVEc4vjs/rs:fit:32:
… (98 chars elided on L138)
139},
140"language": "ru",
Occurrences
10 occurrences · first at L138, also L149, L239 +7 more
Show all 10 locations
Line
File
L138
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L149
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L239
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L250
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L347
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L358
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L386
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L397
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L494
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
L505
research/_raw_data/crpt-mobile-api_2026-06-23/brave/brand_owner.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha2567deba1f0b129d5f1rubric 365aacaView on GitHub
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json×12
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json· json
238"url": "https://docs.crpt.ru/gismt/%D0%9C%D0%BE%D0%B1%D0%B8%D0%BB%D1%8C%D0%BD%D0%BE%D0%B5_%D
… (98 chars elided on L238)
239"long_name": "docs.crpt.ru",
240"img": "https://imgs.search.brave.com/QUXZ7x8OdZyvrJ6oqtkWJGoWZ4lx4BpYjNZXVEc4vjs/rs:fit:32:
… (98 chars elided on L240)
241},
242"language": "ru",
Occurrences
12 occurrences · first at L240, also L251, L266 +9 more
Show all 12 locations
Line
File
L240
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L251
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L266
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L277
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L330
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L341
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L439
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L450
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L543
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L554
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L607
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
L618
research/_raw_data/crpt-mobile-api_2026-06-23/brave/host_path.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha2567deba1f0b129d5f1rubric 365aacaView on GitHub
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json×11
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json· json
151},
152"thumbnail": {
153"src": "https://imgs.search.brave.com/Qy0XM84pX1KgTpoa8wXT08u811-uEELug2tktusa99I/rs:fit:200
… (98 chars elided on L153)
154"original": "https://opengraph.githubassets.com/e459a0e4c20a97a0c9d578846f08b00336217303400f
… (45 chars elided on L154)
155"logo": false
Occurrences
11 occurrences · first at L153, also L197, L337 +8 more
Show all 11 locations
Line
File
L153
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L197
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L337
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L508
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L519
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L697
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L708
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L793
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L804
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L865
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
L876
research/_raw_data/crpt-mobile-api_2026-06-23/brave/li0ard_lib.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha2568152541dc55eb9d2rubric 365aacaView on GitHub
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json×27
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json· json
34"name": "Stack Overflow",
35"url": "https://stackoverflow.com/questions/50568873/check-api-request-body",
36"img": "https://imgs.search.brave.com/4WRMec_wn8Q9LO6DI43kkBvIL6wD5TYCXztC9C9kEI0/rs:fit:32:
… (96 chars elided on L36)
37}
38],
Occurrences
27 occurrences · first at L36, also L52, L195 +24 more
Show all 27 locations
Line
File
L36
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L52
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L195
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L220
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L245
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L270
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L295
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L338
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L349
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L459
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L470
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L497
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L508
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L536
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L547
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L567
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L578
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L642
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L653
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L699
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L710
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L884
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L895
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L919
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L930
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L1046
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
L1057
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_check_body.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha2561ac58c05226876b4rubric 365aacaView on GitHub
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json×20
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json· json
136"url": "https://infostart.ru/1c/articles/1506206/",
137"long_name": "infostart.ru",
138"img": "https://imgs.search.brave.com/risZ6GoSr9tqzk81rvK2pCrln14FQjeWdBygyBRJNX8/rs:fit:32:
… (98 chars elided on L138)
139},
140"language": "ru",
Occurrences
20 occurrences · first at L138, also L149, L213 +17 more
Show all 20 locations
Line
File
L138
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L149
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L213
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L224
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L339
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L350
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L381
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L392
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L412
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L423
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L501
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L512
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L579
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L590
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L655
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L666
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L852
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L863
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L902
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
L913
research/_raw_data/crpt-mobile-api_2026-06-23/brave/mobile_response.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha256506a7da2422b1b1frubric 365aacaView on GitHub
HIGHLong base64-encoded blob hidden in the skill documentationSS-SKILL-INJECT-B64-PAYLOAD-01 · Prompt injection · research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json×13
HIGHonce decoded by the agent, an encoded payload has the same impact class as plain-text injection.
Why it matters

A base64 string of 128+ characters appears in a documentation file. Encoded prompt injection hides the hostile instruction in base64 — invisible to keyword filters — and relies on the agent's ability to decode it at runtime. There is no normal authoring reason to embed a multi-hundred-byte base64 blob in skill docs.

The exact value spotted
excerptresearch/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json· json
259"url": "https://infostart.ru/public/1236219/",
260"long_name": "infostart.ru",
261"img": "https://imgs.search.brave.com/risZ6GoSr9tqzk81rvK2pCrln14FQjeWdBygyBRJNX8/rs:fit:32:
… (98 chars elided on L261)
262},
263"language": "ru",
Occurrences
13 occurrences · first at L261, also L272, L382 +10 more
Show all 13 locations
Line
File
L261
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L272
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L382
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L393
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L472
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L501
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L512
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L535
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L546
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L564
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L575
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L800
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
L811
research/_raw_data/crpt-mobile-api_2026-06-23/brave/reverse_eng.json
How to fix
Remove the encoded blob, or decode it and review what it actually contains.
  1. Decode the base64 string and confirm it is not an instruction directed at the agent.
  2. Move any legitimate binary or signature data into a dedicated file (*.sig, SIGNATURES) outside the documentation.
Framework references
OWASPLLM01ATLASAML.T0051
Trace & refs
ruleSS-SKILL-INJECT-B64-PAYLOAD-01sha256506a7da2422b1b1frubric 365aacaView on GitHub
Supply chainscore 100 · 0 findings
All supply chain checks passedNo findings in this category for the latest scan.pass
Maintenancescore 100 · 0 findings
All maintenance checks passedNo findings in this category for the latest scan.pass
Transparencyscore 100 · 0 findings
All transparency checks passedNo findings in this category for the latest scan.pass
Communityscore 100 · 0 findings
All community checks passedNo findings in this category for the latest scan.pass
Vendor response · right of reply
Are you the maintainer? Submit a response →

Audit the pieces. Scan the whole. Decide.

~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.