Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
50066 analyzed
8097 re-analysis due
988 not analyzable
0 not yet analyzed
4803 source gone
not analyzable
789 too large 199 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 338
- committed secret 6178
- dynamic exec 11834
- obfuscation 3579
- suspicious endpoint 12346
- credential in log 713
- over-broad oauth scope 2550
- suspicious skill script 185
- bundled IDE extension 49
- skill file 187628
- MEDIUM suspicious endpoint vibeinging/dsh-desktop 169.254.169.254 (cloud metadata)
"http://169.254.169.254/latest/meta-data", - HIGH obfuscation vibeinging/dsh-desktop dynamic require()/import()
const databaseModule = await import(`../../server/src/db.js?legacy-capability-test=${Date.now()}`); - HIGH obfuscation vibeinging/dsh-desktop dynamic require()/import()
const database = await import(${JSON.stringify(dbModuleUrl)}); - MEDIUM suspicious endpoint deadsimple-email/deadsimple-email 169.254.169.254 (cloud metadata)
for url in ("http://169.254.169.254/latest/meta-data/", - MEDIUM suspicious endpoint Lifecycle-Innovations-Limited/claude-ops api.telegram.org
const TG_BASE = `https://api.telegram.org/bot${BOT_TOKEN}`; - HIGH obfuscation Lifecycle-Innovations-Limited/claude-ops dynamic require()/import()
const { acquireRefreshLock } = await import(`../refresh-lock.mjs?test=${Date.now()}`); - HIGH obfuscation Lifecycle-Innovations-Limited/claude-ops dynamic require()/import()
const m = await import(${JSON.stringify(`file://${modulePath}`)}); - HIGH dynamic exec manishiitg/coding-agent-loop new Function()
new Function("window", "document", stub)(win, doc); - HIGH dynamic exec manishiitg/coding-agent-loop new Function()
new Function("window", "document", stub)(win, doc); - HIGH dynamic exec manishiitg/coding-agent-loop new Function()
new Function('window', stub)(win) - MEDIUM over-broad oauth scope manishiitg/coding-agent-loop https://www.googleapis.com/auth/documents
'https://www.googleapis.com/auth/documents': { label: 'Docs: read+write', detail: 'Read and modify Google Docs documents.' }, - MEDIUM over-broad oauth scope manishiitg/coding-agent-loop https://www.googleapis.com/auth/spreadsheets
'https://www.googleapis.com/auth/spreadsheets': { label: 'Sheets: read+write', detail: 'Read and modify Google Sheets spreadsheets.' }, - MEDIUM over-broad oauth scope manishiitg/coding-agent-loop https://www.googleapis.com/auth/drive
'https://www.googleapis.com/auth/drive': { label: 'Drive: read+write', detail: 'Read and modify files in Google Drive.' }, - MEDIUM over-broad oauth scope manishiitg/coding-agent-loop gmail.modify
'https://www.googleapis.com/auth/gmail.modify': { label: 'Gmail: full (legacy)', detail: 'Full mailbox access — read, send, and organize. Broader than this connector currently requests; carried over f - HIGH dynamic exec manishiitg/coding-agent-loop new Function()
g,_).replace(/\[CancellationCode\]/g,U),new Function("tryCatch","errorObj","Promise","async",A)(u,d,e,c)},y=[],f=[],s=[],p=0;p<8;++p)y.push(h(p+1)),f.push(g(p+1)),s.push(m(p+1));b=function(l){this._re