Unified AI rules management CLI tool that generates configuration files for various AI development tools
94%
Total Score
healthy
Active releases and development, verified provenance, and a broad contributor base outweigh minor workflow-permission concerns.
All 13 workflows were analyzed with no untrusted checkouts or script injections, and all 36 action references are pinned. Eight workflows use top-level write permissions, and the auditor reported a low-confidence cache-poisoning pattern, so workflow hygiene is a minor caution rather than a severe risk.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-10520 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. rulesync is vulnerable to Prototype Pollution in versions 8.0.0 - 8.5.0. | 8.0.0 - 8.5.0 | Medium |
AIKIDO-2026-10178 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. rulesync is vulnerable to Improper Input Validation in versions 0.1.0 - 6.4.0. | 0.1.0 - 6.4.0 | Medium |
AIKIDO-2026-10124 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. rulesync is vulnerable to Path Traversal in versions 0.68.0 - 6.0.0. | 0.68.0 - 6.0.0 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
zod Version 4.6.5 | — | — |
sury Version 10.0.4 | — | — |
effect Version 3.22.2 | — | — |
globby Version 16.2.4 | — | — |
fastmcp Version 4.22.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.