Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51314 analyzed
7403 re-analysis due
996 not analyzable
0 not yet analyzed
4850 source gone
not analyzable
796 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12011
- obfuscation 3650
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190167
- HIGH dynamic exec rudi193-cmd/willow-2.0 __import__ sink
__import__("os").environ.get( - HIGH dynamic exec rudi193-cmd/willow-2.0 __import__ sink
CODEX_REPO = __import__("os").environ.get("WILLOW_NEST_ROOT", str(__import__("pathlib").Path.home() / "github" / "willow-nest")) - MEDIUM suspicious endpoint rudi193-cmd/willow-2.0 100.1.1.1
monkeypatch.setenv("RATATOSK_GROVE_TAILNET_URL", "http://100.1.1.1:9") - MEDIUM suspicious endpoint rudi193-cmd/willow-2.0 example.ngrok.app
monkeypatch.setenv("RATATOSK_GROVE_NGROK_URL", "https://example.ngrok.app") - HIGH dynamic exec ManojCyberMaster/dronacharya eval()/exec()
exec(compile(code, "<matcher>", "exec"), namespace) # noqa: S102 — validated above, sandboxed here - HIGH obfuscation ztrack dynamic require()/import()
const module = await import(`./entry.tsx?viz5Scenario=${++scenarioId}`); - HIGH obfuscation ztrack dynamic require()/import()
const module = await import(`./entry.tsx?viz4Scenario=${++scenarioId}`); - HIGH dynamic exec bosch-smart-home-camera-mcp eval()/exec()
exec( # noqa: S102 - HIGH committed secret gemini-web-mcp-cli Google API key
AIzaSy…(39 chars, redacted) - HIGH dynamic exec maml/lightning-fm-mcp new Function()
const fn = new Function( - MEDIUM suspicious endpoint kfuras/notipo-app eu.posthog.com (telemetry)
ui_host: "https://eu.posthog.com", - MEDIUM suspicious endpoint kfuras/notipo-app eu.i.posthog.com (telemetry)
api_host: "https://eu.i.posthog.com", - MEDIUM suspicious endpoint kfuras/notipo-app eu.i.posthog.com (telemetry)
host: process.env.POSTHOG_HOST || "https://eu.i.posthog.com", - HIGH credential in log kfuras/notipo-app credential in log
console.log(` API key: ${apiKey}`); - HIGH dynamic exec TIMPSs/timps new Function()
const fn = new Function('path', `