Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50108 analyzed
8067 re-analysis due
988 not analyzable
0 not yet analyzed
4804 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6180
- dynamic exec 11839
- obfuscation 3598
- suspicious endpoint 12356
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187702
- HIGH committed secret hayahaya-ai/ariadne committed .env
env file shipped with populated values - HIGH committed secret hayahaya-ai/ariadne committed .env
env file shipped with populated values - MEDIUM suspicious endpoint ashlrai/ashlr-plugin sentry.io (telemetry)
const url = `https://sentry.io/api/0/projects/${sentryOrg}/${sentryProject}/issues/?limit=${limit}&query=is:unresolved`; - HIGH obfuscation ashlrai/ashlr-plugin dynamic require()/import()
const mod = await import("../servers/_stats?t=" + Date.now()); - HIGH committed secret ashlrai/ashlr-plugin OpenAI key
sk-zyx…(24 chars, redacted) - MEDIUM suspicious endpoint E13ctr0N/marketolog api.telegram.org
TG_API = "https://api.telegram.org" - MEDIUM suspicious endpoint E13ctr0N/marketolog api.telegram.org
TG_API = "https://api.telegram.org" - MEDIUM suspicious endpoint E13ctr0N/marketolog api.telegram.org
TG_API = "https://api.telegram.org" - HIGH suspicious skill script aegntic/cldcde suspicious bundled script
| 6 | 500 | $(python3 -c "print(int(500 * (0.5 if '$SCENARIO' == 'pessimistic' else (1.75 if '$SCENARIO' == 'optimistic' else 1.0))))") | $(python3 -c "print((0.5 - 1.0) * 100 if '$SCENARIO' - MEDIUM suspicious endpoint aegntic/cldcde sentry.io (telemetry)
- Sign up at https://sentry.io - MEDIUM suspicious endpoint aegntic/cldcde sentry.io (telemetry)
url: 'https://sentry.io', - HIGH credential in log aegntic/cldcde credential in log
console.log(`Found ${passwordInputs.length} password inputs`); - HIGH committed secret zbl1998-sdjn/MASE-agent-memory OpenAI key
sk-sec…(27 chars, redacted) - MEDIUM over-broad oauth scope Asm3r96/geistr-core https://www.googleapis.com/auth/cloud-platform
"https://www.googleapis.com/auth/cloud-platform", - HIGH committed secret KaedeAatou/belvedere Google API key
AIzaSy…(39 chars, redacted)