Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51197 analyzed
7502 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12007
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190152
- HIGH obfuscation glatinone/mcp-local-to-hosted-deployment-fix dynamic require()/import()
const root=new URL('../',import.meta.url).pathname; const {issueToken,validateToken,expireToken}=await import(root+'runtime/auth.mjs'); const {validateArgs,approvalMatches}=await import(root+'runtime/ - HIGH obfuscation glatinone/mcp-local-to-hosted-deployment-fix dynamic require()/import()
const { issueToken, expireToken } = await import(root + 'runtime/auth.mjs'); - HIGH dynamic exec ancilis/ancilis __import__()
__import__( - HIGH dynamic exec ancilis/ancilis __import__ sink
env={"HOME": str(home), "PATH": __import__("os").environ.get("PATH", "")}, - MEDIUM suspicious endpoint ancilis/ancilis docs.sentry.io (telemetry)
"spec_url": "https://docs.sentry.io/api/events/", - HIGH dynamic exec dengyier/OpenWorkProof eval()/exec()
exec(compile(source, name, "exec"), module.__dict__) # noqa: S102 - HIGH dynamic exec dengyier/OpenWorkProof eval()/exec()
exec(compile(source, name, "exec"), module.__dict__) - HIGH dynamic exec 1clawAI/browser-bridge eval()
await this.#eval(sessionId, `document.querySelector(${JSON.stringify(grant.passwordSelector)})?.form?.submit()`); - HIGH dynamic exec 1clawAI/browser-bridge eval()
const focused = await this.#eval( - HIGH dynamic exec 1clawAI/browser-bridge eval()
const v = await this.#eval(sessionId, read); - HIGH committed secret Rorogogogo/nomoreide GitHub fine-grained PAT
github…(38 chars, redacted) - HIGH dynamic exec tianyilt/qzcli_tool __import__()
__import__(mod) - MEDIUM suspicious endpoint archmax-ai/archmax 169.254.169.254 (cloud metadata)
expect(await validateSafeUrl("http://169.254.169.254/latest/meta-data/")).toBe( - HIGH dynamic exec ZhaoXingPeng/DBJavaGenix __import__()
__import__(mod_name) - MEDIUM suspicious endpoint Open330/context-compress 192.0.0.1
"https://192.0.0.1/",