Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51197 analyzed
7502 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12007
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190152
- HIGH bundled IDE extension mumo-chat/mumo-vscode untrusted-exec (medium)
runs its entry point in untrusted workspaces (untrustedWorkspaces.supported) - HIGH obfuscation aoto-tech/CellFence dynamic require()/import()
await import(${JSON.stringify(`${pathToFileURL(tracePath).href}?plain-import`)}); - HIGH obfuscation aoto-tech/CellFence dynamic require()/import()
await import(`${pathToFileURL(cliPath).href}?missingArgv=${Date.now()}`); - HIGH dynamic exec aoto-tech/CellFence eval()
async eval(_script, numKeysOrOptions, ...args) { - HIGH dynamic exec aoto-tech/CellFence eval()
eval(script: string, numKeysOrOptions: number | { keys: string[]; arguments: string[] }, ...args: (string | number)[]): Promise<unknown>; - HIGH credential in log QBT-Labs/openmm-mcp credential in log
console.log(` Private Key: ${wallet.privateKey}\n`); - HIGH dynamic exec GhostlyGawd/engineering-board __import__ sink
env = dict(__import__('os').environ, CLAUDE_PROJECT_DIR=str(ROOT)) - HIGH dynamic exec wisent-wire-mcp __import__()
imported = __import__(mod, fromlist=[a.name for a in node.names]) - MEDIUM suspicious endpoint NimuStudio/NimuQDock-dsh 169.254.169.254 (cloud metadata)
'http://169.254.169.254/latest/meta-data/', - HIGH committed secret salahuddinuqaili/agy-slack Slack token
xoxp-y…(20 chars, redacted) - HIGH committed secret salahuddinuqaili/agy-slack Slack token
xoxp-y…(20 chars, redacted) - HIGH dynamic exec dilolabs/nosia new Function()
unction u(e){for(let t of e)t.oncommand=new Function("event",t.getAttribute("oncommand"))}let c=new Mu - HIGH credential in log ohneben/Anytype-MCP credential in log
console.log(`\nYour API KEY: ${apiKey}`); - HIGH dynamic exec JacobisEpic/playbookdiff indirect eval
return this || (0, eval)("this"); - MEDIUM suspicious endpoint Mihailorama/scrapefold t.me
("https://t.me/durov", "telegram"),