Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51197 analyzed
7502 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12007
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190152
- HIGH committed secret kamolc4/slack-mcp-server Slack token
xoxb-y…(19 chars, redacted) - HIGH dynamic exec zcag/defter eval()
eval(node: Node): CellValue - HIGH dynamic exec Tabtii/blender-mcp-server eval()/exec()
exec(code, namespace) - MEDIUM suspicious endpoint LucasLeguizamo/open-ticket 169.254.169.254 (cloud metadata)
["cloud metadata IP", "http://169.254.169.254/latest/meta-data/"], - MEDIUM suspicious endpoint LucasLeguizamo/open-ticket 169.254.169.254 (cloud metadata)
safeFetchHtml("http://169.254.169.254/latest/meta-data/"), - HIGH credential in log LucasLeguizamo/open-ticket credential in log
console.log(`Demo API key (buy_ticket): ${DEMO_API_KEY}`); - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai www.fullstory.com (telemetry)
target("tech-fullstory", "https://www.fullstory.com/", "tech/SaaS", "primary", fullPolicy, ["session_replay_fingerprinting_review", "cookie_notice_availability"], ["FullStory"]), - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai segment.com (telemetry)
target("tech-segment", "https://segment.com/", "tech/SaaS", "primary", fullPolicy, ["cross_border_endpoint_review", "session_replay_fingerprinting_review"], ["Segment", "Google"]), - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai www.google-analytics.com (telemetry)
"https://www.google-analytics.com/analytics.js", - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai www.fullstory.com (telemetry)
session_replay_observed: "https://www.fullstory.com/", - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai www.google-analytics.com (telemetry)
requestUrls: [`https://www.google-analytics.com/g/collect?reviewed=${index}`], - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai 1.1.1.1
assert.equal(normalizeUrl("https://1.1.1.1"), "https://1.1.1.1/"); - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai 169.254.169.254 (cloud metadata)
"http://169.254.169.254", - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai sentry.io (telemetry)
ied("Functional Software, Inc.", "US", "https://sentry.io/astro-assets/resources/legal/International-Data-Transfers-With-Sentry-2024-01-19.pdf", "Sentry international data transfer assessment", "Sentr - MEDIUM suspicious endpoint ergoveritas1-alt/certscore.ai mixpanel.com (telemetry)
verified("Mixpanel, Inc.", "US", "https://mixpanel.com/legal/app-store-privacy-details/", "Mixpanel developer privacy guidance", "Mixpanel identifies San Francisco headquarters separately from its EU