Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51308 analyzed
7409 re-analysis due
996 not analyzable
0 not yet analyzed
4850 source gone
not analyzable
796 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12011
- obfuscation 3650
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190167
- HIGH committed secret 0Mattias/bettermemory AWS access key id
AKIA4Z…(20 chars, redacted) - HIGH committed secret 0Mattias/bettermemory GitHub token
ghp_4K…(40 chars, redacted) - HIGH committed secret 0Mattias/bettermemory Anthropic key
sk-ant…(99 chars, redacted) - HIGH committed secret 0Mattias/bettermemory AWS access key id
AKIA4Z…(20 chars, redacted) - HIGH committed secret 0Mattias/bettermemory private key
PEM private key block (redacted) - HIGH dynamic exec jeff-nasseri/mikrotik-mcp __import__()
module = __import__(f"mcp_mikrotik.scope.{module_name}", fromlist=["*"]) - HIGH dynamic exec HiAi-gg/docsmint new Function()
new Function( - HIGH dynamic exec HiAi-gg/docsmint eval()
eval( - MEDIUM suspicious endpoint HiAi-gg/docsmint 93.184.216.34
"https://93.184.216.34/image", - HIGH dynamic exec HiAi-gg/docsmint eval()
async eval(_script: string, _keys: number, ...args: Array<string | number>) { - HIGH dynamic exec delimit-ai/delimit-mcp-server __import__()
mod = __import__(import_name) - MEDIUM suspicious endpoint delimit-ai/delimit-mcp-server api.telegram.org
url = f"https://api.telegram.org/bot{bot_token}/sendMessage" - HIGH dynamic exec delimit-ai/delimit-mcp-server __import__()
__import__(pkg) - HIGH dynamic exec ZiChenWang114514/cdxml-toolkit-community __import__()
self.module = __import__(assembly_name, fromlist=["StructureData"]) - HIGH dynamic exec ZiChenWang114514/cdxml-toolkit-community __import__()
_cs_module = __import__(ASSEMBLY, fromlist=["StructureData", "ReactionData"])