Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50064 analyzed
8099 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6178
- dynamic exec 11834
- obfuscation 3579
- suspicious endpoint 12346
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187628
- HIGH committed secret shawn-durrani/membro Anthropic key
sk-ant…(49 chars, redacted) - HIGH obfuscation asynx6/tokenzip dynamic require()/import()
await import(`./hooks/${argv[1] || 'claude-code'}.mjs`); - HIGH dynamic exec toolbase unsafe yaml.load()
data = yaml.load(f) - HIGH obfuscation cckyros/goal-acceptance dynamic require()/import()
const mod = await import("data:text/javascript;base64," + Buffer.from(code).toString("base64")); - HIGH dynamic exec myrrazor/atlas-tasker vm exec
vm.runInNewContext(script, context, { filename: 'app.js' }); - HIGH dynamic exec Sahith59/AgentMem-OS __import__ sink
__import__("os").environ.get("AGENTMEM_OS_TEST_LIVE_REDIS") != "1", - HIGH committed secret Abidemialade/mylonite Anthropic key
sk-ant…(37 chars, redacted) - HIGH committed secret Abidemialade/mylonite Anthropic key
sk-ant…(36 chars, redacted) - MEDIUM suspicious endpoint Abidemialade/mylonite 169.254.169.254 (cloud metadata)
assert not host_allowed("http://169.254.169.254/latest/meta-data/", al) - MEDIUM suspicious endpoint git-agentic/pkg-registry 169.254.169.254 (cloud metadata)
() => assertAllowedTarballUrl("http://169.254.169.254/latest/meta-data", registry, []), - HIGH obfuscation git-agentic/pkg-registry base64 decode → exec sink
const stage = Buffer.from(packed, "base64").toString("utf8"); - HIGH dynamic exec git-agentic/pkg-registry new Function()
const factory = new Function("_", "return function " + functionName + "(){ return _; }"); - HIGH obfuscation git-agentic/pkg-registry base64 decode → exec sink
var stage = Buffer.from(_0x, "base64").toString("utf8"); - HIGH dynamic exec git-agentic/pkg-registry eval()
eval(stage); - HIGH credential in log VineetV2/peon-mem credential in log
await logger.log("request_in", { path: "/sessions", apiKey: "sk-live-shouldhide" });