Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50108 analyzed
8067 re-analysis due
988 not analyzable
0 not yet analyzed
4804 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6180
- dynamic exec 11839
- obfuscation 3598
- suspicious endpoint 12356
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187702
- HIGH dynamic exec r3dz4r/datapulse-my eval()/exec()
exec(load_code_cell(6), namespace) - HIGH dynamic exec r3dz4r/datapulse-my __import__ sink
root = Path(__import__("os").environ.get("DATAPULSE_REPO_ROOT", ROOT)).resolve() - MEDIUM suspicious endpoint off-grid-ai/OGAD developer.mixpanel.com (telemetry)
docsUrl: 'https://developer.mixpanel.com/', - MEDIUM suspicious endpoint off-grid-ai/OGAD amplitude.com (telemetry)
docsUrl: 'https://amplitude.com/docs', - MEDIUM suspicious endpoint off-grid-ai/OGAD posthog.com (telemetry)
docsUrl: 'https://posthog.com/docs', - MEDIUM suspicious endpoint off-grid-ai/OGAD mcp.posthog.com (telemetry)
url: 'https://mcp.posthog.com/sse', - MEDIUM suspicious endpoint off-grid-ai/OGAD docs.sentry.io (telemetry)
docsUrl: 'https://docs.sentry.io/product/sentry-mcp/', - HIGH obfuscation off-grid-ai/OGAD dynamic require()/import()
const runtime = await import(`${pathToFileURL(runtimeEntry).href}?contract-check=${Date.now()}`) - HIGH committed secret Digital-Process-Tools/claude-supertool Stripe live key
sk_liv…(28 chars, redacted) - HIGH committed secret Digital-Process-Tools/claude-supertool GitHub token
ghp_01…(40 chars, redacted) - HIGH dynamic exec Digital-Process-Tools/claude-supertool eval()/exec()
exec(compile(f.read_text(encoding="utf-8"), str(f), "exec"), {}) - HIGH committed secret Digital-Process-Tools/claude-supertool GitLab token
glpat-…(26 chars, redacted) - MEDIUM suspicious endpoint Digital-Process-Tools/claude-supertool 169.254.169.254 (cloud metadata)
"http://169.254.169.254/latest/meta-data/iam/security-credentials/role", - HIGH dynamic exec Digital-Process-Tools/claude-supertool eval()/exec()
return eval(proc.stdout.strip()) - HIGH dynamic exec Digital-Process-Tools/claude-supertool eval()/exec()
eval(annotation, namespace) # noqa: S307 - our own module's own text