Skip to content

Add AgentAudit Security Badge ✅#219

Open
starbuck100 wants to merge 1 commit intogetsentry:mainfrom
starbuck100:add-agentaudit-badge
Open

Add AgentAudit Security Badge ✅#219
starbuck100 wants to merge 1 commit intogetsentry:mainfrom
starbuck100:add-agentaudit-badge

Conversation

@starbuck100
Copy link

AgentAudit Security Badge

This PR adds a security badge from AgentAudit, an open security registry for AI packages.

Your package has been officially audited by AgentAudit and received a Safe rating with no security findings.

🔗 View full audit report

What is AgentAudit?

AgentAudit is a transparency-first security registry that audits MCP servers, AI skills, and agent packages. Our audits use a 3-pass methodology (understand → detect → classify) to minimize false positives while catching real vulnerabilities.

Copy link
Contributor

@cursor cursor bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 1 potential issue.

Bugbot Autofix is OFF. To automatically fix reported issues with Cloud Agents, enable Autofix in the Cursor dashboard.


## Installation

[![AgentAudit Security](https://img.shields.io/badge/AgentAudit-Safe-brightgreen?logo=data:image/svg%2Bxml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyNCAyNCI+PHBhdGggZmlsbD0id2hpdGUiIGQ9Ik0xMiAxTDMgNXY2YzAgNS41NSAzLjg0IDEwLjc0IDkgMTIgNS4xNi0xLjI2IDktNi40NSA5LTEyVjVsLTktNHoiLz48L3N2Zz4=)](https://www.agentaudit.dev/skills/xcodebuildmcp)
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Unverified external service badge links to unknown domain

Medium Severity

The badge links to agentaudit.dev, an external third-party service with limited web presence and no verifiable connection to established security auditing organizations. Adding a "Safe" security badge from an unverified source to the project README could mislead users into a false sense of security and lends the project's reputation to promote a third-party service. This pattern (unsolicited PRs adding third-party badges) is a known social engineering vector for building credibility for new services.

Fix in Cursor Fix in Web

Triggered by project rule: Bugbot Review Guide for XcodeBuildMCP

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant