Code analysis
static source read inferred
Static code-analysis findings — hidden prompt content in shipped skill files, committed secrets, dynamic-exec sinks, and suspicious call-home endpoints — across the analyzed catalogue. Heuristic, pure, no code executed; every row deep-links to its source. Click a kind to filter.
51197 analyzed
7502 re-analysis due
995 not analyzable
0 not yet analyzed
4849 source gone
not analyzable
795 too large 200 no source
Running analyzer v33. The scanner changelog explains what each version detects and when it changed.
- hidden prompt 369
- committed secret 6298
- dynamic exec 12007
- obfuscation 3647
- suspicious endpoint 12542
- credential in log 718
- over-broad oauth scope 2556
- suspicious skill script 197
- bundled IDE extension 50
- skill file 190152
- MEDIUM suspicious endpoint @sideboard-ai/core us.posthog.com (telemetry)
defaultHost: "https://us.posthog.com", - MEDIUM suspicious endpoint @sideboard-ai/core app.posthog.com (telemetry)
tokenDocs: "https://app.posthog.com/settings/user-api-keys", - MEDIUM suspicious endpoint @sideboard-ai/core sentry.io (telemetry)
integrations.sentryAuthToken ? integrations.sentryHost || "https://sentry.io" : void 0 - MEDIUM suspicious endpoint @sideboard-ai/core us.posthog.com (telemetry)
integrations.posthogPersonalApiKey ? integrations.posthogHost || "https://us.posthog.com" : void 0 - MEDIUM suspicious endpoint @sideboard-ai/core sentry.io (telemetry)
tokenDocs: "https://sentry.io/settings/account/api/auth-tokens/", - MEDIUM suspicious endpoint @sideboard-ai/core us.posthog.com (telemetry)
defaultHost: "https://us.posthog.com", - MEDIUM suspicious endpoint @sideboard-ai/core app.posthog.com (telemetry)
tokenDocs: "https://app.posthog.com/settings/user-api-keys", - HIGH committed secret MuhammadUsmanGM/claude-code-best-practices Slack token
xoxb-y…(19 chars, redacted) - HIGH dynamic exec uipath-mcp eval()/exec()
exec(code, namespace) - HIGH dynamic exec uipath-mcp eval()/exec()
exec(code, namespace) - HIGH obfuscation albertbaarsma/horizon dynamic require()/import()
const { buildReport, reportAsText } = await import(`file:///${tmp.replace(/\\/g, '/')}`) - MEDIUM over-broad oauth scope albertbaarsma/horizon https://mail.google.com/
href={`https://mail.google.com/mail/u/0/#inbox/${m.id}`} - HIGH dynamic exec subodhkc/ai-appsec eval()
eval(llmOutput); - HIGH dynamic exec rejifald/StitchAPI eval()
async eval() { - HIGH dynamic exec rejifald/StitchAPI eval()
async eval(script, _numKeys, ...args) {