Code analysis

static source read inferred

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage 85% of 59,151 analyzable servers
50064 analyzed
8099 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source

Running analyzer v33. The scanner changelog explains what each version detects and when it changed.

code findings 15 shown
  1. HIGH dynamic exec crisnahine/chameleon __import__() module = __import__(module_name, fromlist=[factory_attr])
  2. HIGH committed secret crisnahine/chameleon AWS access key id AKIA2X…(20 chars, redacted)
  3. HIGH dynamic exec cdeust/prd-spec-generator new Function() const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
  4. HIGH committed secret lyse-labs/lyse Slack token xoxb-0…(24 chars, redacted)
  5. HIGH committed secret lyse-labs/lyse GitHub token ghp_01…(44 chars, redacted)
  6. HIGH dynamic exec 1cyberlangke1/eggtart vm exec vm.runInNewContext(script, { setBlock, fillBlock }, { timeout: timeoutMs })
  7. HIGH committed secret FlowElement-xinliuyuansu/m_flow private key PEM private key block (redacted)
  8. HIGH dynamic exec FlowElement-xinliuyuansu/m_flow __import__() module = __import__(module_path, fromlist=[class_name])
  9. HIGH dynamic exec FlowElement-xinliuyuansu/m_flow __import__() loader_module = __import__(
  10. HIGH dynamic exec FlowElement-xinliuyuansu/m_flow __import__() mod = __import__(mod_path, fromlist=[cls_name])
  11. MEDIUM over-broad oauth scope alexanderkrauck/mailindex-mcp https://mail.google.com/ GMAIL_MAIL_SCOPE = "https://mail.google.com/"
  12. HIGH dynamic exec Lars-Albinsson/playwright-react-debug-mcp new Function() const fn = new Function('root', 'depth', 'maxDepth', `return ${summarizer}(root, depth, maxDepth)`);
  13. MEDIUM suspicious endpoint barkain/madrox 169.254.169.254 (cloud metadata) "https://169.254.169.254/latest/meta-data/", # AWS metadata SSRF
  14. MEDIUM suspicious endpoint syntinal-co/Talaria-Code 126.255.255.255 'http://126.255.255.255',
  15. MEDIUM suspicious endpoint syntinal-co/Talaria-Code 128.0.0.1 'http://128.0.0.1',