Code analysis

static source read inferred

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage 86% of 59,695 analyzable servers
51192 analyzed
7507 re-analysis due
995 not analyzable
1 not yet analyzed
4848 source gone
not analyzable
795 too large 200 no source

Running analyzer v33. The scanner changelog explains what each version detects and when it changed.

code findings 15 shown
  1. MEDIUM suspicious endpoint stabgan/openrouter-mcp-multimodal 169.254.169.254 (cloud metadata) image_path: 'http://169.254.169.254/latest/meta-data/',
  2. MEDIUM suspicious endpoint cliwant/mcp-sam-gov 169.254.169.254 (cloud metadata) url: "https://169.254.169.254/latest/meta-data/",
  3. MEDIUM suspicious endpoint albidev/bdh-graph-harness 1.2.3.4 assert _api_url("/api/query", host="1.2.3.4", port=9999) == "http://1.2.3.4:9999/api/query"
  4. HIGH dynamic exec blendrelay-mcp eval()/exec() exec(compiled, namespace, namespace)
    blendrelay_mcp-0.7.3/src/blendrelay_blender/ general.py :455
  5. HIGH credential in log tinyorbitvn/codex-imagegen-mcp credential in log log.info("thử", { client_secret: "không-được-lộ" });
  6. MEDIUM suspicious endpoint escapeWu/perplexity-ai api.telegram.org url = f"https://api.telegram.org/bot{bot_token}/sendMessage"
  7. MEDIUM suspicious endpoint f1shyondrugs/metis 169.254.169.254 (cloud metadata) "http://169.254.169.254/latest/meta-data",
  8. MEDIUM over-broad oauth scope f1shyondrugs/metis https://www.googleapis.com/auth/cloud-platform "https://www.googleapis.com/auth/cloud-platform",
  9. HIGH committed secret f1shyondrugs/metis Google OAuth client secret GOCSPX…(35 chars, redacted)
  10. HIGH dynamic exec f1shyondrugs/metis new Function() const compiled = new Function("scope", `"use strict"; return (${mapped});`) as (scope: Record<string, number>) => unknown;
  11. HIGH dynamic exec offx-zinth/SMP eval()/exec() exec('raise TypeError("Invalid parameter type")') if p.get("fail") else {"status": "ok"}
  12. HIGH obfuscation athompson83/data-foundry dynamic require()/import() const loaded = (await import(`${pathToFileURL(bundled).href}?test=${Date.now()}`)) as {
  13. MEDIUM suspicious endpoint athompson83/data-foundry 8.8.8.8 'https://8.8.8.8',
  14. HIGH committed secret sandbox-quantum/switch Slack token xoxb-d…(21 chars, redacted)
  15. MEDIUM suspicious endpoint sandbox-quantum/switch amplitude.com (telemetry) docsUrl: 'https://amplitude.com/docs/amplitude-ai/amplitude-mcp',