Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50877 analyzed
7738 re-analysis due
994 not analyzable
1 not yet analyzed
4843 source gone
not analyzable
793 too large 201 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6279
- dynamic exec 11963
- obfuscation 3642
- suspicious endpoint 12517
- credential in log 718
- over-broad oauth scope 2539
- suspicious skill script 197
- bundled IDE extension 50
- skill file 189917
- HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function('console', ` - HIGH dynamic exec beyondwin/FixThis new Function()
const fn = new Function( - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function('notificationCenter', 'window', ` - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${fsmSrc}\n${ucSrc}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${source}; return { evaluateStale, MAX_PREVIEW_AGE_MS };`); - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${src}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${fsmSrc}\n${ucSrc}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${src}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
return new Function( - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(` - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${workspaceSrc}; ${historySrc}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${sources}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${sources}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
const factory = new Function(`${boundarySrc}\n${storageSrc}; return { - HIGH dynamic exec beyondwin/FixThis new Function()
return new Function(`