Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50066 analyzed
8097 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6178
- dynamic exec 11834
- obfuscation 3579
- suspicious endpoint 12346
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187628
- HIGH dynamic exec NovadaLabs/proxy4agent new Function()
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - MEDIUM suspicious endpoint MongLong0214/stock-ai-newsletter www.google-analytics.com (telemetry)
e.co https://vitals.vercel-insights.com https://www.google-analytics.com https://analytics.google.com https://www.googletagmanager.com https://*.clarity.ms https://c.bing.com", - MEDIUM suspicious endpoint MongLong0214/stock-ai-newsletter www.google-analytics.com (telemetry)
<link rel="preconnect" href="https://www.google-analytics.com" crossOrigin="anonymous" /> - HIGH suspicious skill script Mnexa-AI/e2a suspicious bundled script
eval "$(t_python -c 'import json,shlex,os - HIGH obfuscation Mnexa-AI/e2a dynamic require()/import()
const { loadEnv } = await import(`./env.ts?no-target=${Date.now()}`); - HIGH committed secret Mibayy/token-savior GitHub token
ghp_AA…(43 chars, redacted) - HIGH dynamic exec MetriLLM/metrillm constructor escape
input.constructor.constructor("return process")(); - MEDIUM suspicious endpoint MetriLLM/metrillm eu.i.posthog.com (telemetry)
const POSTHOG_HOST = "https://eu.i.posthog.com"; - HIGH credential in log MendleM/Pipepost credential in log
console.log(` access_token: ${tokenResponse.access_token}`); - HIGH credential in log MeltFlexDevs/skills credential in log
console.log(`✅ Signed in. API key saved to ${saveApiKey(key)}`); - MEDIUM suspicious endpoint MUSE-CODE-SPACE/content-genie-mcp 169.254.169.254 (cloud metadata)
urls: ['http://localhost:8080/admin', 'http://169.254.169.254/'], - HIGH credential in log MPP32/MPP32 credential in log
console.error(`[mpp32] MPP32_SOLANA_PRIVATE_KEY: ${fp(SOLANA_PRIVATE_KEY)}`); - MEDIUM suspicious endpoint MP-Tool/komodo-mcp-server 1.2.3.4
address: z.string().optional().describe("The ws/s address of the periphery client (e.g., http://1.2.3.4:8120)"), - HIGH bundled IDE extension MCPower-Security/mcpower-proxy eager-activation (medium)
activationEvents includes "*" — runs on every window load - MEDIUM suspicious endpoint MCPower-Security/mcpower-proxy 128.0.0.1
["http://128.0.0.1/", true],