Skip to content

Add MseeP.ai badge - #284

Open
mseep-ai wants to merge 1 commit into
OpenCoworkAI:mainfrom
mseep-ai:add-mseep-badge
Open

Add MseeP.ai badge#284
mseep-ai wants to merge 1 commit into
OpenCoworkAI:mainfrom
mseep-ai:add-mseep-badge

Conversation

@mseep-ai

@mseep-ai mseep-ai commented Jul 6, 2026

Copy link
Copy Markdown

Hi there,

This pull request shares a security update on open-cowork.

We also have an entry for open-cowork in our directory, MseeP.ai, where we provide regular security and trust updates on your app.

We invite you to add our badge for your MCP server to your README to help your users learn from a third party that provides ongoing validation of open-cowork.

You can easily take control over your listing for free: visit it at https://mseep.ai/app/opencoworkai-open-cowork.

Thanks,

The MseeP Team
MCP servers you can trust


MseeP.ai Security Assessment Badge

Here are our latest evaluation results of open-cowork

Security Scan Results

Security Score: 78/100

Risk Level: moderate

Scan Date: 2026-07-06

Score starts at 100, deducts points for security issues, and adds points for security best practices

Detected Vulnerabilities

High Severity

  • protobufjs
    • [{'source': 1117571, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'Arbitrary code execution in protobufjs', 'url': 'https://github.com/advisories/GHSA-xq3m-2v4x-88gg', 'severity': 'critical', 'cwe': ['CWE-94'], 'cvss': {'score': 9.8, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'range': '<7.5.5'}, {'source': 1118641, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Code injection through bytes field defaults in generated toObject code', 'url': 'https://github.com/advisories/GHSA-66ff-xgx4-vchm', 'severity': 'high', 'cwe': ['CWE-94'], 'cvss': {'score': 0, 'vectorString': None}, 'range': '<=7.5.5'}, {'source': 1118924, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Denial of service from crafted field names in generated code', 'url': 'https://github.com/advisories/GHSA-2pr8-phx7-x9h3', 'severity': 'moderate', 'cwe': ['CWE-20'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '<=7.5.5'}, {'source': 1118926, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Prototype injection in generated message constructors', 'url': 'https://github.com/advisories/GHSA-fx83-v9x8-x52w', 'severity': 'moderate', 'cwe': ['CWE-1321'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '<=7.5.5'}, {'source': 1118928, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Code generation gadget after prototype pollution', 'url': 'https://github.com/advisories/GHSA-75px-5xx7-5xc7', 'severity': 'high', 'cwe': ['CWE-94', 'CWE-1321'], 'cvss': {'score': 8.1, 'vectorString': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}, 'range': '<=7.5.5'}, {'source': 1118930, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Process-wide denial of service through unsafe option paths', 'url': 'https://github.com/advisories/GHSA-jvwf-75h9-cwgg', 'severity': 'high', 'cwe': ['CWE-1321'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '<=7.5.5'}, {'source': 1118932, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobuf.js: Denial of service through unbounded protobuf recursion', 'url': 'https://github.com/advisories/GHSA-685m-2w69-288q', 'severity': 'high', 'cwe': ['CWE-674'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '<=7.5.5'}, {'source': 1118935, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobufjs has overlong UTF-8 decoding', 'url': 'https://github.com/advisories/GHSA-q6x5-8v7m-xcrf', 'severity': 'moderate', 'cwe': ['CWE-176'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '<=7.5.5'}, {'source': 1119378, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobufjs: Denial of Service via unbounded recursive JSON descriptor expansion', 'url': 'https://github.com/advisories/GHSA-jggg-4jg4-v7c6', 'severity': 'moderate', 'cwe': ['CWE-674'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '<=7.5.7'}, {'source': 1120742, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobufjs : Schema-derived names can shadow runtime-significant properties', 'url': 'https://github.com/advisories/GHSA-f38q-mgvj-vph7', 'severity': 'moderate', 'cwe': ['CWE-674', 'CWE-754'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}, 'range': '<=7.6.2'}, {'source': 1120799, 'name': 'protobufjs', 'dependency': 'protobufjs', 'title': 'protobufjs: Denial of service through unbounded Any expansion during JSON conversion', 'url': 'https://github.com/advisories/GHSA-wcpc-wj8m-hjx6', 'severity': 'high', 'cwe': ['CWE-674'], 'cvss': {'score': 7.5, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}, 'range': '<=7.6.0'}]
    • Fixed in version: unknown

Medium Severity

  • @aws-sdk/xml-builder

    • ['fast-xml-parser']
    • Fixed in version: unknown
  • @hono/node-server

    • [{'source': 1116281, 'name': '@hono/node-server', 'dependency': '@hono/node-server', 'title': '@hono/node-server: Middleware bypass via repeated slashes in serveStatic', 'url': 'https://github.com/advisories/GHSA-92pp-h63x-v22m', 'severity': 'moderate', 'cwe': ['CWE-22'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}, 'range': '<1.19.13'}]
    • Fixed in version: unknown
  • @protobufjs/utf8

    • [{'source': 1118933, 'name': '@protobufjs/utf8', 'dependency': '@protobufjs/utf8', 'title': 'protobufjs has overlong UTF-8 decoding', 'url': 'https://github.com/advisories/GHSA-q6x5-8v7m-xcrf', 'severity': 'moderate', 'cwe': ['CWE-176'], 'cvss': {'score': 5.3, 'vectorString': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}, 'range': '<=1.1.0'}]
    • Fixed in version: unknown
  • ... and 28 more medium severity vulnerabilities

Security Findings

Medium Severity Issues

  • semgrep: Use of child_process.exec() with dynamic input detected. This can lead to command injection.
    • Location: src/main/mcp/software-dev-server-example.ts
    • Line: 458

This security assessment was conducted by MseeP.ai, an independent security validation service for MCP servers. Visit our website to learn more about our security reviews.

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Review mode: initial

Findings

No issues found. The change adds a single image badge link to the README. This is a minor, non-functional change with no impact on correctness, security, performance, or maintainability.

  • [Minor] The badge image is loaded from an external domain (https://mseep.net/). If that domain is compromised, the image could be replaced with malicious content (e.g., a phishing image or tracking pixel). However, this is common practice for open-source badges and the risk is low. Consider hosting the badge image within the repository or using a trusted badge service to eliminate this dependency.

Summary

Review mode: initial. The PR adds a security badge to the README. No code or logic changes. Residual risks: the badge image is externally hosted, which could be a vector for content replacement or tracking. Suggested improvement: host the badge internally or use a well-known badge service. Otherwise, the change is acceptable.

Testing

Not run (no code changes to test).

Open Cowork Bot

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant