Code analysis

static source read inferred

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage 85% of 59,151 analyzable servers
50067 analyzed
8096 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source

Running analyzer v33. The scanner changelog explains what each version detects and when it changed.

code findings 15 shown
  1. MEDIUM suspicious endpoint cyanheads/atlas-mcp-server analytics.google.com (telemetry) {"title": "Web Vitals Tracking", "url": "https://analytics.google.com/web-vitals"}
  2. MEDIUM over-broad oauth scope epaproditus/google-workspace-mcp-server gmail.modify 'https://www.googleapis.com/auth/gmail.modify',
  3. MEDIUM over-broad oauth scope juecd/programmable-email gmail.modify const SCOPES: string[] = ['https://www.googleapis.com/auth/gmail.modify'];
  4. HIGH dynamic exec smithery-ai/cli new Function() const stdioFn = new Function(
  5. HIGH credential in log smithery-ai/cli credential in log console.log(`SMITHERY_API_KEY=${apiKey}`)
  6. MEDIUM over-broad oauth scope gongrzhe/gmail-mcp-server gmail.modify 'https://www.googleapis.com/auth/gmail.modify',
  7. HIGH dynamic exec steel-dev/steel-mcp-server new Function() const isolate = <T>(helper: T): T => new Function(`return (${helper});`)() as T;
  8. HIGH dynamic exec steel-dev/steel-mcp-server eval() async eval(script: string, numberOfKeys: number, ...args: Array<string | number>): Promise<unknown> {
  9. HIGH dynamic exec steel-dev/steel-mcp-server eval() eval(script: string, numberOfKeys: number, ...args: Array<string | number>): Promise<unknown>;
  10. MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader app.posthog.com (telemetry) .ZP.init(e.apiKey,{api_host:e.apiHost||"https://app.posthog.com",capture_pageview:!1,disable_session_recording:!t,loaded:e=>{k.XK||e.opt_out_capturing()}}))}captureEvent(e){return async t=>{C.ZP.captu
  11. MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader cdn.segment.com (telemetry) global-segment-analytics-key",i);t.src="https://cdn.segment.com/analytics.js/v1/" + key + "/analytics.min.js";var r=document.getElementsByTagName("script")[0];r.parentNode.insertBefore(t,r);analytics.
  12. MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader cdn.heapanalytics.com (telemetry) ype="text/javascript",r.async=!0,r.src="https://cdn.heapanalytics.com/js/heap-"+e+".js";var a=document.getElementsByTagName("script")[0];a.parentNode.insertBefore(r,a);for(var n=function(e){return fun
  13. MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader sentry.io (telemetry) level};return n&&i&&(f.$sentry_url=(r||"https://sentry.io/organizations/")+n+"/issues/?project="+i+"&query="+t.event_id),e.exceptions.sendExceptionEvent(f),t}}var iT,iC,iO,i$,iA=B(function e(t,n,i,r,s
  14. MEDIUM suspicious endpoint angrysky56/mcp-windows-website-downloader app.posthog.com (telemetry) turn on debug mode and open a ticket on https://app.posthog.com/home#panel=support%3Asupport%3A."),$.critical(e)}}},ei=function(e){var t={};return Y(e,function(e,n){I(e)&&e.length>0&&(t[n]=e)}),t},er=
  15. HIGH dynamic exec angrysky56/mcp-windows-website-downloader eval() (b=e.getAttribute("data-requiremodule")),g=F[e.getAttribute("data-requirecontext")])}(g?g.defQueue:R).push([b,c,d])};define.amd={jQuery:!0};g.exec=function(b){return eval(b)};g(q)}})(this);