Code analysis

static source read inferred

Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.

analysis coverage 85% of 59,151 analyzable servers
50064 analyzed
8099 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source

Running analyzer v33. The scanner changelog explains what each version detects and when it changed.

code findings 15 shown
  1. MEDIUM suspicious endpoint justintanner/apicity api.telegram.org parsedOptions.baseURL ?? "https://api.telegram.org/bot{token}"
  2. HIGH committed secret justintanner/apicity committed .env env file shipped with populated values
  3. HIGH dynamic exec mariusei/scantool pickle.loads() assert all(pickle.loads(p.read_bytes()) is not None for p in directory.glob("*.pkl"))
  4. HIGH dynamic exec mariusei/scantool pickle.loads() return pickle.loads(stored)
  5. MEDIUM over-broad oauth scope sweetrb/apple-mail-mcp https://mail.google.com/ scope: this.options.scope || "https://mail.google.com/",
  6. HIGH dynamic exec sweetrb/apple-mail-mcp new Function() const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
  7. MEDIUM over-broad oauth scope sweetrb/apple-mail-mcp https://mail.google.com/ scope: this.options.scope || "https://mail.google.com/",
  8. HIGH dynamic exec lumizone/postsider eval() async eval(script: string, numKeys: number, ...args: string[]) {
  9. MEDIUM suspicious endpoint lumizone/postsider t.me releaseURL: `https://t.me/${
  10. HIGH committed secret lumizone/postsider OpenAI key sk-cje…(28 chars, redacted)
  11. HIGH credential in log lumizone/postsider credential in log console.log(` │ Password: ${setupPassword.padEnd(28)}│`);
  12. HIGH dynamic exec sweetrb/apple-notes-mcp new Function() const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
  13. HIGH dynamic exec sweetrb/apple-numbers-mcp new Function() const makeValidate = new Function(`${names_1.default.self}`, `${names_1.default.scope}`, sourceCode);
  14. HIGH dynamic exec lacs-project/sysknife vm exec const fetchWithProgress = vm.runInNewContext(`${source}\nfetchWithProgress;`, {
  15. HIGH committed secret youbotapi/gpt-image-mcp OpenAI key sk-pro…(32 chars, redacted)