Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50029 analyzed
8115 re-analysis due
988 not analyzable
0 not yet analyzed
4801 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6177
- dynamic exec 11823
- obfuscation 3573
- suspicious endpoint 12346
- credential in log 713
- over-broad oauth scope 2548
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187726
- MEDIUM suspicious endpoint @wonderwhy-er/desktop-commander www.google-analytics.com (telemetry)
const GA_BASE_URL = `https://www.google-analytics.com/mp/collect?measurement_id=${GA_MEASUREMENT_ID}&api_secret=${GA_API_SECRET}`; - HIGH dynamic exec @wonderwhy-er/desktop-commander new Function()
ludes("Cloudflare"))return!1;try{return new Function(""),!0}catch{return!1}});function ti(e){if(ro(e)===!1)return!1;let t=e.constructor;if(t===void 0||typeof t!="function")return!0;let n=t.prototype;r - HIGH dynamic exec @wonderwhy-er/desktop-commander new Function()
ludes("Cloudflare"))return!1;try{return new Function(""),!0}catch{return!1}});function et(e){if(ht(e)===!1)return!1;let t=e.constructor;if(t===void 0||typeof t!="function")return!0;let n=t.prototype;r - MEDIUM suspicious endpoint @wonderwhy-er/desktop-commander www.google-analytics.com (telemetry)
const GA_BASE_URL = `https://www.google-analytics.com/mp/collect?measurement_id=${GA_MEASUREMENT_ID}&api_secret=${GA_API_SECRET}`; - MEDIUM suspicious endpoint @wonderwhy-er/desktop-commander www.google-analytics.com (telemetry)
const GA_BASE_URL = `https://www.google-analytics.com/mp/collect?measurement_id=${GA_MEASUREMENT_ID}&api_secret=${GA_API_SECRET}`; - HIGH dynamic exec @settlemint/sdk-mcp eval()
eval(key, value) { - HIGH dynamic exec @settlemint/sdk-mcp new Function()
const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode); - HIGH dynamic exec creo-mcp eval()/exec()
exec(code) - HIGH dynamic exec creo-mcp eval()/exec()
result = eval(measure.strip().replace(" ", "+")) * IN - HIGH dynamic exec creo-mcp eval()/exec()
result = eval(measure) - HIGH dynamic exec chaimi-keep-mcp concat require()
s=require('os'),fs=require('fs'),crypto=require('crypt'+'o'),{exec}=require(_0x757ff0(0x71e)+'_proc'+'ess'),util=require(_0x757ff0(0x20f)),execPromise=util[_0x757ff0(0x3a4)+'sify'](exec);function getV - HIGH dynamic exec @railway/mcp-server new Function()
new Function("exports", snapshotContents)(data);