Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51224 analyzed
7479 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12010
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190157
- HIGH dynamic exec openlegion-ai/openlegion __import__()
backend.client.containers.get.side_effect = __import__( - MEDIUM over-broad oauth scope openlegion-ai/openlegion https://mail.google.com/
for host in ("https://mail.google.com/inbox", - HIGH dynamic exec openlegion-ai/openlegion __import__()
router = __import__( - HIGH committed secret openlegion-ai/openlegion OpenAI key
sk-sec…(31 chars, redacted) - MEDIUM over-broad oauth scope openlegion-ai/openlegion https://mail.google.com/
await mgr.navigate("a1", "https://mail.google.com/") - HIGH committed secret openlegion-ai/openlegion OpenAI key
sk-sup…(27 chars, redacted) - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.99
302, headers={"location": "https://93.184.216.99/elsewhere"}, - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.50
AS_ISSUER = "https://93.184.216.50" - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.34
MCP_URL = "https://93.184.216.34/mcp" - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.99
url="https://93.184.216.99/mcp", agents=["*"], - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.34
url="https://93.184.216.34/mcp", - HIGH committed secret openlegion-ai/openlegion Anthropic key
sk-ant…(48 chars, redacted) - HIGH committed secret openlegion-ai/openlegion Anthropic key
sk-ant…(48 chars, redacted) - HIGH committed secret openlegion-ai/openlegion Anthropic key
sk-ant…(54 chars, redacted) - MEDIUM suspicious endpoint openlegion-ai/openlegion 93.184.216.34
url="https://93.184.216.34/mcp",