Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51314 analyzed
7403 re-analysis due
996 not analyzable
0 not yet analyzed
4850 source gone
not analyzable
796 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12011
- obfuscation 3650
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190167
- MEDIUM over-broad oauth scope Chere3/hermes-automation-stack gmail.modify
"https://www.googleapis.com/auth/gmail.modify", - HIGH dynamic exec bruchris/canvas-lms-mcp new Function()
const widget = new Function( - HIGH obfuscation moerasermax/tkflyc-ai-cli dynamic require()/import()
const restarted = await import(`../dist/core/updater.js?restart=${serial}`); - HIGH dynamic exec Unchained-Labs/cortex __import__()
"channel": {"type": "string", "enum": list(__import__( - HIGH dynamic exec Unchained-Labs/cortex eval()/exec()
exec(compile(code, f"{name}.py", "exec"), module.__dict__) # noqa: S102 - MEDIUM suspicious endpoint just-every/mcp-read-website-fast 169.254.169.254 (cloud metadata)
'http://169.254.169.254/', - MEDIUM suspicious endpoint mshadmanrahman/root-kg api.telegram.org
f"https://api.telegram.org/bot{token}/sendMessage", - HIGH dynamic exec gougoujiang/buildmax eval()
async eval(expr) { - HIGH dynamic exec gougoujiang/buildmax eval()
async eval(expr) { - HIGH dynamic exec Ryanabcraft/zeroreal new Function()
const ZSParse = new Function(fs.readFileSync(__dirname + "/core/parser.js", "utf8") + "; return ZSParse;")(); - HIGH dynamic exec Ryanabcraft/zeroreal new Function()
const P = new Function( - HIGH obfuscation yadimon/steuer-spar-erklaerung-mcp dynamic require()/import()
prewarmPool = await import(`../dist/worker-prewarm.js?startup-timeout=${randomUUID()}`); - HIGH dynamic exec yadimon/steuer-spar-erklaerung-mcp new Function()
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - HIGH committed secret seraph-quest/seraph OpenAI key
sk-sup…(24 chars, redacted) - MEDIUM suspicious endpoint seraph-quest/seraph 169.254.169.254 (cloud metadata)
mgr.update_server("gh", url="http://169.254.169.254/latest/meta-data")