Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51308 analyzed
7409 re-analysis due
996 not analyzable
0 not yet analyzed
4850 source gone
not analyzable
796 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12011
- obfuscation 3650
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190167
- MEDIUM suspicious endpoint jigyasudham/veto 169.254.169.254 (cloud metadata)
'SSRF: submit internal URLs (http://169.254.169.254, http://localhost) to URL-accepting parameters', - HIGH committed secret TobiiNT/SshWarden Slack token
xoxb-0…(26 chars, redacted) - HIGH committed secret TobiiNT/SshWarden GitHub token
ghp_01…(41 chars, redacted) - HIGH committed secret TobiiNT/SshWarden private key
PEM private key block (redacted) - HIGH committed secret TobiiNT/SshWarden private key
PEM private key block (redacted) - HIGH committed secret TobiiNT/SshWarden GitHub token
ghp_01…(41 chars, redacted) - MEDIUM suspicious endpoint syamaner/roastpilot-agent 169.254.169.254 (cloud metadata)
"http://169.254.169.254/latest/meta-data/", config=BeanSourcingConfig() - MEDIUM suspicious endpoint rekog-labs/MCP-Nest 169.254.169.254 (cloud metadata)
['link-local', 'https://169.254.169.254/client.json'], - MEDIUM over-broad oauth scope rekog-labs/MCP-Nest https://www.googleapis.com/auth/spreadsheets
scope: ['https://www.googleapis.com/auth/spreadsheets'], - HIGH dynamic exec mgonzalez01/Chonks eval()/exec()
exec(compile(src, "chunking_main_reference.py", "exec"), mod.__dict__) - MEDIUM suspicious endpoint andrewchmr/mxprobe api.telegram.org
assert.equal(r.calls[0]?.url, "https://api.telegram.org/bottok/sendMessage"); - MEDIUM suspicious endpoint andrewchmr/mxprobe api.telegram.org
const res = await fetchImpl(`https://api.telegram.org/bot${tgToken}/sendMessage`, { - HIGH credential in log andrewchmr/mxprobe credential in log
console.info(`mxprobe-server ${VERSION} on http://${HOST}:${PORT} db=${DB_PATH} telegram=${notifier.configured.telegram} email=${notifier.configured.email} stripe=${!!(env.STRIPE_SECRET_KEY && env.STR - HIGH obfuscation BeatAPI/BeatDesign dynamic require()/import()
const cryptoModule = await import(${JSON.stringify(moduleUrl)}); - MEDIUM suspicious endpoint BeatAPI/BeatDesign 169.254.169.254 (cloud metadata)
'https://169.254.169.254',