Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51224 analyzed
7479 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12010
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190157
- HIGH dynamic exec ArcadeData/arcadedb new Function()
new Function("return (" + source + ")"); - MEDIUM suspicious endpoint apideck-libraries/mcp eu.i.posthog.com (telemetry)
const POSTHOG_BATCH_URL = 'https://eu.i.posthog.com/batch'; - MEDIUM suspicious endpoint apideck-libraries/mcp eu.i.posthog.com (telemetry)
const POSTHOG_BATCH_URL = 'https://eu.i.posthog.com/batch'; - HIGH obfuscation adrianczuczka/mason dynamic require()/import()
"test/smoke.test.mjs": `import test from 'node:test';\nimport assert from 'node:assert/strict';\n${sources.map((f, i) => `test(${JSON.stringify(f)},async()=>{const module=await import(${JSON.stringify - MEDIUM suspicious endpoint thoughtspot/mcp-server api.mixpanel.com (telemetry)
"https://api.mixpanel.com/track", - MEDIUM suspicious endpoint thoughtspot/mcp-server api.mixpanel.com (telemetry)
"https://api.mixpanel.com/track", - MEDIUM suspicious endpoint thoughtspot/mcp-server api.mixpanel.com (telemetry)
const TRACK_ENDPOINT = "https://api.mixpanel.com/track"; - HIGH dynamic exec paichart/paichart eval()
inline: eval(extractConst(TOOL_SCHEMAS, 'WORKFLOW_EXECUTION_MODES') || 'null'), - MEDIUM suspicious endpoint paichart/paichart 169.254.169.254 (cloud metadata)
'http://169.254.169.254/', // cloud metadata - MEDIUM suspicious endpoint paichart/paichart 169.254.169.254 (cloud metadata)
endpoint: 'http://169.254.169.254/mcp', - MEDIUM suspicious endpoint paichart/paichart 169.254.169.254 (cloud metadata)
'http://169.254.169.254/', 'http://10.0.0.5/', 'http://[::ffff:7f00:1]/', 'http://[::]/', 'http://localhost./', - MEDIUM suspicious endpoint paichart/paichart 169.254.169.254 (cloud metadata)
| \`169.254.169.254\` | Cloud metadata (AWS) | \`http://169.254.169.254/latest/meta-data\` | - HIGH credential in log paichart/paichart credential in log
console.log(`Password: ${tempPassword}`); - HIGH credential in log paichart/paichart credential in log
console.log(` ${password}`); - HIGH committed secret paichart/paichart OpenAI key
sk-cmg…(28 chars, redacted)