Code analysis

static source read inferred

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage 86% of 59,690 analyzable servers
51160 analyzed
7536 re-analysis due
994 not analyzable
0 not yet analyzed
4848 source gone
not analyzable
794 too large 200 no source

Running analyzer v33. The scanner changelog explains what each version detects and when it changed.

code findings 15 shown
  1. MEDIUM suspicious endpoint AnIayana/high-performance-mcp-server 93.184.216.34 url: "http://93.184.216.34/data",
  2. MEDIUM suspicious endpoint AnIayana/high-performance-mcp-server 169.254.169.254 (cloud metadata) "http://169.254.169.254:80/",
  3. HIGH obfuscation AnIayana/high-performance-mcp-server dynamic require()/import() const deepModule = await import("${packageJson.name}/dist/index.js");
  4. HIGH committed secret ysskrishna/markdown-convert-mcp Slack token xoxb-y…(19 chars, redacted)
  5. HIGH committed secret ysskrishna/markdown-convert-mcp Slack token xoxb-y…(19 chars, redacted)
  6. HIGH obfuscation pasichDev/todo-mcp dynamic require()/import() const viewers = await import(${JSON.stringify(viewersModule)});
  7. HIGH obfuscation pasichDev/todo-mcp dynamic require()/import() const { decryptFromBuffer } = await import(`${CRYPTO_MODULE}?first-run=${randomUUID()}`);
  8. HIGH obfuscation pasichDev/todo-mcp dynamic require()/import() const device = await import(${JSON.stringify(deviceModule)});
  9. HIGH dynamic exec superfly/sprites-deepseek-plugin unsafe yaml.load() return yaml.load(handle, Loader=CordisLoader)
  10. HIGH dynamic exec superfly/sprites-deepseek-plugin unsafe yaml.load() return yaml.load(text, Loader=CordisLoader)
  11. HIGH dynamic exec iTao-AI/multimodal-knowledge-engine eval()/exec() exec(receipt._RUNTIME_EVIDENCE_SOURCE, {"__name__": "__main__"}) # noqa: S102
  12. HIGH dynamic exec developerDesinger/ai-brain eval() eval(proxyInfo);
  13. HIGH committed secret developerDesinger/ai-brain committed .env env file shipped with populated values
  14. HIGH dynamic exec danielyayla/veri new Function() const fn = new Function(
  15. HIGH dynamic exec danielyayla/veri new Function() const fn = new Function(