Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50023 analyzed
8114 re-analysis due
987 not analyzable
0 not yet analyzed
4801 source gone
not analyzable
789 too large 198 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6177
- dynamic exec 11817
- obfuscation 3573
- suspicious endpoint 12343
- credential in log 713
- over-broad oauth scope 2548
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187709
- MEDIUM suspicious endpoint figma-developer-mcp us.i.posthog.com (telemetry)
LsUHU4TGGpgAiscm8nhjudHgAJzAdzXkJV",lt="https://us.i.posthog.com",M,te,oe,N=!0,re=!1,Ie=[],Fe=new nt;function ne(e,t){let o=e.filter(Boolean);return o.length===0?t():Fe.run(o,t)}function mt(e){return - HIGH dynamic exec @serdnaley/metabase-mcp new Function()
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - HIGH dynamic exec @hasna/conversations new Function()
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - HIGH dynamic exec decocms new Function()
(e?self.eval(e.createScript("","true")):new Function("true")).call(self),!0}catch{return!1}}class h{constructor(){this._cachedCanUseEval=null}_canUseEval(e){return this._cachedCanUseEval===null&&(this - HIGH dynamic exec decocms new Function()
(a?self.eval(a.createScript("","true")):new Function("true")).call(self),!0}catch{return!1}}class A{constructor(){this._cachedCanUseEval=null}_canUseEval(a){return this._cachedCanUseEval===null&&(this - MEDIUM suspicious endpoint decocms analytics.google.com (telemetry)
4:{label:"Google Analytics",consoleUrl:"https://analytics.google.com/analytics/web/#/admin",consoleLinkKey:"reportsOnboarding.saBinding.ga4.openConsole" - HIGH dynamic exec decocms new Function()
peof JSON<"u"&&JSON.parse?JSON.parse(r):new Function("return ("+r+");")():r}var Ds=re();const Fa={registerMap:function(r,e,t){if(e.svg){var a=new W6(r,e.svg);Ds.set(r,a)}else{var n=e.geoJson||e.geoJSO - HIGH dynamic exec decocms new Function()
($=this.opts.code.process($,C));const j=new Function(`${o.default.self}`,`${o.default.scope}`,$)(this,this.scope.get());if(this.scope.value(O,{ref:j}),j.errors=nu - MEDIUM suspicious endpoint @sentry/mcp-server sentry.io (telemetry)
"get_issue_tag_values(issueUrl='https://sentry.io/issues/PROJECT-123/', tagKey='browser')", - MEDIUM suspicious endpoint @sentry/mcp-server my-org.sentry.io (telemetry)
"get_issue_breadcrumbs(issueUrl='https://my-org.sentry.io/issues/PROJECT-123/')", - MEDIUM suspicious endpoint @sentry/mcp-server my-organization.sentry.io (telemetry)
"get_issue_activity(issueUrl='https://my-organization.sentry.io/issues/PROJECT-123/')", - MEDIUM suspicious endpoint @sentry/mcp-server sentry.sentry.io (telemetry)
"get_issue_details(issueUrl='https://sentry.sentry.io/issues/6916805731/?project=4509062593708032&query=is%3Aunresolved')", - MEDIUM suspicious endpoint @sentry/mcp-server us.sentry.io (telemetry)
typically the region-specific URL like 'https://us.sentry.io'. For self-hosted Sentry installations, this parameter is usually not needed and should be omitted. You can find the correct regionUrl from - MEDIUM suspicious endpoint @sentry/mcp-server sentry.io (telemetry)
"get_issue_tag_values(issueUrl='https://sentry.io/issues/PROJECT-123/', tagKey='browser')", - MEDIUM suspicious endpoint @sentry/mcp-server my-org.sentry.io (telemetry)
"get_issue_breadcrumbs(issueUrl='https://my-org.sentry.io/issues/PROJECT-123/')",