Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51224 analyzed
7479 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12010
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190157
- HIGH dynamic exec leizd/deepseek eval()/exec()
exec(compile(code, "<oracle>", "exec"), ns) # noqa: S102 - HIGH dynamic exec leizd/deepseek eval()/exec()
exec(compile(ERRORS.read_text(encoding="utf-8"), str(ERRORS), "exec"), namespace) # noqa: S102 - HIGH dynamic exec leizd/deepseek eval()/exec()
exec(compile(ERRORS.read_text(encoding="utf-8"), str(ERRORS), "exec"), namespace) # noqa: S102 - HIGH dynamic exec leizd/deepseek eval()/exec()
exec(compile(_extract(files_source, name), str(FILES), "exec"), namespace) # noqa: S102 - HIGH dynamic exec leizd/deepseek eval()/exec()
exec(compile(segment, str(UTILS), "exec"), namespace) # noqa: S102 - HIGH dynamic exec leizd/deepseek __import__()
module = __import__(module_name) - HIGH committed secret yesonsys03-web/VibeLign AWS access key id
AKIAQQ…(20 chars, redacted) - HIGH committed secret yesonsys03-web/VibeLign OpenAI key
sk-AAA…(35 chars, redacted) - HIGH committed secret yesonsys03-web/VibeLign OpenAI key
sk-AAA…(35 chars, redacted) - HIGH committed secret yesonsys03-web/VibeLign Anthropic key
sk-ant…(54 chars, redacted) - HIGH dynamic exec reporails/cli unsafe yaml.load()
return yaml.load(content, Loader=_YamlLoader) - HIGH obfuscation mrtdlgc/revertwtf dynamic require()/import()
const shard = await import(`./data/shards/${shardId}.json`, { with: { type: "json" } }); - HIGH committed secret pleasedodisturb/web-agent-comparison Google API key
AIzaSy…(39 chars, redacted) - HIGH committed secret pleasedodisturb/web-agent-comparison Google API key
AIzaSy…(39 chars, redacted) - HIGH committed secret pleasedodisturb/web-agent-comparison Google API key
AIzaSy…(39 chars, redacted)