Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50108 analyzed
8067 re-analysis due
988 not analyzable
0 not yet analyzed
4804 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6180
- dynamic exec 11839
- obfuscation 3598
- suspicious endpoint 12356
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187702
- HIGH committed secret ashlrai/phantom-secrets Anthropic key
sk-ant…(34 chars, redacted) - HIGH committed secret ashlrai/phantom-secrets OpenAI key
sk-rea…(32 chars, redacted) - HIGH committed secret ashlrai/phantom-secrets Stripe live key
sk_liv…(28 chars, redacted) - HIGH dynamic exec ashlrai/phantom-secrets new Function()
new Function("exports", "require", "module", output)( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - HIGH dynamic exec ashlrai/phantom-secrets new Function()
const fn = new Function( - MEDIUM suspicious endpoint ashlrai/phantom-secrets us.i.posthog.com (telemetry)
api_host: process.env.NEXT_PUBLIC_POSTHOG_HOST || "https://us.i.posthog.com", - HIGH committed secret mmadfox/go-crx3 private key
PEM private key block (redacted) - HIGH committed secret mmadfox/go-crx3 private key
PEM private key block (redacted) - HIGH obfuscation moerasermax/ai-cli-mcp-source dynamic require()/import()
const restarted = await import(`../dist/core/updater.js?restart=${serial}`); - MEDIUM over-broad oauth scope haule2901/google-workspace-mcp https://www.googleapis.com/auth/drive
? 'https://www.googleapis.com/auth/drive'