Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50067 analyzed
8096 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6178
- dynamic exec 11834
- obfuscation 3579
- suspicious endpoint 12346
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187628
- MEDIUM suspicious endpoint cyanheads/atlas-mcp-server analytics.google.com (telemetry)
{"title": "Web Vitals Tracking", "url": "https://analytics.google.com/web-vitals"} - MEDIUM over-broad oauth scope epaproditus/google-workspace-mcp-server gmail.modify
'https://www.googleapis.com/auth/gmail.modify', - MEDIUM over-broad oauth scope juecd/programmable-email gmail.modify
const SCOPES: string[] = ['https://www.googleapis.com/auth/gmail.modify']; - HIGH dynamic exec smithery-ai/cli new Function()
const stdioFn = new Function( - HIGH credential in log smithery-ai/cli credential in log
console.log(`SMITHERY_API_KEY=${apiKey}`) - MEDIUM over-broad oauth scope gongrzhe/gmail-mcp-server gmail.modify
'https://www.googleapis.com/auth/gmail.modify', - HIGH dynamic exec steel-dev/steel-mcp-server new Function()
const isolate = <T>(helper: T): T => new Function(`return (${helper});`)() as T; - HIGH dynamic exec steel-dev/steel-mcp-server eval()
async eval(script: string, numberOfKeys: number, ...args: Array<string | number>): Promise<unknown> { - HIGH dynamic exec steel-dev/steel-mcp-server eval()
eval(script: string, numberOfKeys: number, ...args: Array<string | number>): Promise<unknown>; - MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader app.posthog.com (telemetry)
.ZP.init(e.apiKey,{api_host:e.apiHost||"https://app.posthog.com",capture_pageview:!1,disable_session_recording:!t,loaded:e=>{k.XK||e.opt_out_capturing()}}))}captureEvent(e){return async t=>{C.ZP.captu - MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader cdn.segment.com (telemetry)
global-segment-analytics-key",i);t.src="https://cdn.segment.com/analytics.js/v1/" + key + "/analytics.min.js";var r=document.getElementsByTagName("script")[0];r.parentNode.insertBefore(t,r);analytics. - MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader cdn.heapanalytics.com (telemetry)
ype="text/javascript",r.async=!0,r.src="https://cdn.heapanalytics.com/js/heap-"+e+".js";var a=document.getElementsByTagName("script")[0];a.parentNode.insertBefore(r,a);for(var n=function(e){return fun - MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader sentry.io (telemetry)
level};return n&&i&&(f.$sentry_url=(r||"https://sentry.io/organizations/")+n+"/issues/?project="+i+"&query="+t.event_id),e.exceptions.sendExceptionEvent(f),t}}var iT,iC,iO,i$,iA=B(function e(t,n,i,r,s - MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader app.posthog.com (telemetry)
turn on debug mode and open a ticket on https://app.posthog.com/home#panel=support%3Asupport%3A."),$.critical(e)}}},ei=function(e){var t={};return Y(e,function(e,n){I(e)&&e.length>0&&(t[n]=e)}),t},er= - HIGH dynamic exec angrysky56/mcp-windows-website-downloader eval()
(b=e.getAttribute("data-requiremodule")),g=F[e.getAttribute("data-requirecontext")])}(g?g.defQueue:R).push([b,c,d])};define.amd={jQuery:!0};g.exec=function(b){return eval(b)};g(q)}})(this);