security
Security
Every MCP risk signal in one place — CVEs, tool safety, drift, naming, licenses. Heuristic: review signals, not verdicts.
45 CRITICAL
3664 HIGH
531 MEDIUM
1207 LOW
11 NONE
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
6275 analyzed
297 re-analysis due
1444 not analyzable
9267 not yet analyzed
711 source gone
Running analyzer v17. The scanner changelog explains what each version detects and when it changed.
- hidden prompt82
- committed secret188
- dynamic exec375
- suspicious endpoint175
- token-log85
- oauth-scope112
- skill-script60
- ide-extension2
- skill file11681
- HIGH dynamic exec@vpxa/aikitvm exec
- [ ] **eval/Function prevention**: No dynamic code execution from user input (\`eval()\`, \`new Function()\`, \`vm.runInNewContext()\`) - HIGH dynamic exec@vpxa/aikitnew Function()
- [ ] **eval/Function prevention**: No dynamic code execution from user input (\`eval()\`, \`new Function()\`, \`vm.runInNewContext()\`) - LOW token-logbrilliant-directories-mcpcredential in log
console.log(` claude mcp add ${serverName} -- npx -y brilliant-directories-mcp --api-key ${apiKey} --url ${apiUrl}`); - LOW skill-scriptaiwgsuspicious bundled script
eval "$(python3 -c " - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \ - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: ```bash - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: # Fallback to fanart.tv if CAA unavailable - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \ - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: ```bash - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: -H "Authorization: token ${GITHUB_TOKEN}" \ - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: ```bash - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: # Fallback to fanart.tv if CAA unavailable - HIGH hidden promptaiwgskill: skill-exfil
secret→sink: - MEDIUM suspicious endpointharness-mcp-v21.2.3.4
" {list:{elements:[{cluster:'staging', url:'https://1.2.3.4'}, {cluster:'prod', url:'https://2.3.4.5'}]}}\n" +