github Rust re-analysis due deep scan · partial (162/2,132 files)
unconfirmed MCP
ChronoAIProject/NyxID
Connect AI agents to any API, anywhere. Securely. Open-source gateway that proxies requests, injects credentials automatically, punches through NAT to reach localhost services, and wraps REST APIs as MCP tools. Per-agent isolation. Never expose a raw key.
Drift inferred · capture-to-capture
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
- HIGH code analysis flagged committed secret ×4 in ChronoAIProject/NyxID
transport stdio counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
No tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed commit f496ca5 · analyzer v33 · 3h ago
skills & prompt files 19
- agent-rules ChronoAIProject-NyxID-f496ca5/CLAUDE.md
- skill ChronoAIProject-NyxID-f496ca5/integrations/cursor-plugin/skills/nyxid/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-agent-profile-management/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-automation/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-channels-delivery/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-codex-exec-node-setup/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-codex-exec-workflow-sample/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-feasibility-advisor/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-platform-map/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-scheduler/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-service-publisher/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-team-builder/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-triage/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/aevatar-workflow-authoring/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/fallback-to-calling-agent/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/firecrawl-via-nyxid/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/github-via-nyxid/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/nyxid-service-skill-authoring/SKILL.md
- skill ChronoAIProject-NyxID-f496ca5/skills/nyxid/SKILL.md
danger signals16
- suspicious endpoint t.me ChronoAIProject-NyxID-f496ca5/frontend/src/hooks/use-approvals.test.tsx :70
mockPost.mockResolvedValue({ link_url: "https://t.me/x" }); - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
ChronoAIProject-NyxID-f496ca5/frontend/src/lib/telemetry.test.ts :34
host: "https://us.i.posthog.com", - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
ChronoAIProject-NyxID-f496ca5/frontend/src/lib/telemetry.ts :38
const NYXID_PUBLIC_TELEMETRY_HOST = "https://us.i.posthog.com"; - suspicious endpoint t.me ChronoAIProject-NyxID-f496ca5/frontend/src/schemas/providers.test.ts :163
photo_url: "https://t.me/i/userpic/photo.jpg", - suspicious endpoint us.posthog.com (telemetry)
expected for this server's purpose
ChronoAIProject-NyxID-f496ca5/frontend/src/wizard-entry.test.tsx :118
endpoint_url: "https://us.posthog.com", - suspicious endpoint t.me ChronoAIProject-NyxID-f496ca5/mobile/src/components/TelegramLinkModal.tsx :128
const webUrl = `https://t.me/${linkInfo.bot_username}?start=${linkInfo.link_code}`; - suspicious endpoint us.i.posthog.com (telemetry)
expected for this server's purpose
ChronoAIProject-NyxID-f496ca5/mobile/src/lib/telemetry.ts :70
const NYXID_PUBLIC_TELEMETRY_HOST = 'https://us.i.posthog.com'; - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform ChronoAIProject-NyxID-f496ca5/frontend/src/components/assistant/assistant-org-integration-action-dialog.test.tsx :38
nt","private_key":"private"}', scopes: "https://www.googleapis.com/auth/cloud-platform", serviceSlugs: [], targetOrgId: "org-production" }); - over-broad OAuth scope https://www.googleapis.com/auth/cloud-platform ChronoAIProject-NyxID-f496ca5/frontend/src/components/assistant/assistant-org-integration-action-dialog.tsx :90
const [scopes, setScopes] = useState("https://www.googleapis.com/auth/cloud-platform"); - over-broad OAuth scope delete_repo ChronoAIProject-NyxID-f496ca5/frontend/src/components/dashboard/add-key-dialog.test.tsx :662
scope: "delete_repo", - over-broad OAuth scope delete_repo ChronoAIProject-NyxID-f496ca5/frontend/src/lib/assistant/approvals.test.ts :100
tool_name: "delete_repo", - committed secret private key ChronoAIProject-NyxID-f496ca5/backend/src/crypto/apple_client_secret.rs :109
PEM private key block (redacted) - committed secret private key ChronoAIProject-NyxID-f496ca5/backend/src/services/gcp_sa_service.rs :344
PEM private key block (redacted) - committed secret private key ChronoAIProject-NyxID-f496ca5/backend/src/test_utils.rs :1765
PEM private key block (redacted) - committed secret Google API key ChronoAIProject-NyxID-f496ca5/mobile/google-services.json :18
AIzaSy…(39 chars, redacted) - suspicious bundled script suspicious bundled script ChronoAIProject-NyxID-f496ca5/skills/nyxid/scripts/install.sh :115
if curl --proto '=https' --tlsv1.2 -fsSL "$INSTALLER_URL" | sh; then
evidence-backed
findings quoted directly from the published source artifact — not inferred
code files: 1690
filesystem 19
- fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/scripts/assert-mock-footprint.mjs :1
import { readFile, readdir, stat } from "node:fs/promises"; - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/scripts/install-wizard-bundle.mjs :20
import fs from "node:fs" - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/features/docs/manifest.test.ts :2
import { existsSync } from "node:fs"; - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/lib/assistant/canonical-command-guard.test.ts :1
import { readdirSync, readFileSync, statSync } from "node:fs"; - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/test/interop.test.ts :1
import { readFileSync } from "node:fs"; - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/test/release-integrity.test.ts :2
import { mkdtemp, readFile, rm } from "node:fs/promises"; - fs ChronoAIProject-NyxID-f496ca5/frontend/vite-plugins/release-integrity.ts :2
import fs from "node:fs"; - fs (weak) ChronoAIProject-NyxID-f496ca5/frontend/vite.config.ts :6
import fs from "node:fs" - fs (weak) ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/session.browser.test.mjs :5
import { mkdtemp, readFile, rm, writeFile } from "node:fs/promises"; - fs ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/worker.mjs :43
writeFileSync, realpathSync, existsSync } from "node:fs"; - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/build-android.js :29
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/build-ios.js :16
const fs = require("fs");
show 7 more
- fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/bump-version.js :14
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/check-native-sync.js :4
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/clean.js :16
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/lib/load-env.js :11
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/patch-android-build-gradle.js :11
const fs = require('fs'); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/submit-android.js :17
const fs = require("fs"); - fs (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/submit-ios.js :23
const fs = require("fs");
shell / exec 6
- shell (weak) ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/session.browser.test.mjs :2
import { spawn } from "node:child_process"; - shell ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/worker.mjs :47
import { execFileSync, spawn } from "node:child_process"; - shell (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/build-android.js :28
const { execSync } = require("child_process"); - shell (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/build-ios.js :15
const { execSync } = require("child_process"); - shell (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/check-native-sync.js :3
const { execFileSync } = require("child_process"); - shell (weak) ChronoAIProject-NyxID-f496ca5/mobile/scripts/submit-ios.js :22
const { execSync } = require("child_process");
network 19
- net (weak) ChronoAIProject-NyxID-f496ca5/frontend/scripts/verify-aevatar-action-wake.mjs :51
const response = await fetch(`${baseUrl}${path}`, { - net ChronoAIProject-NyxID-f496ca5/frontend/src/components/cli-wizard/auth-flows.tsx :250
void fetch( - net (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/components/cli-wizard/client.test.ts :54
await window.fetch("/api/v1/keys"); - net ChronoAIProject-NyxID-f496ca5/frontend/src/components/cli-wizard/client.ts :226
const response = await fetch("/api/proxy/complete", { - net ChronoAIProject-NyxID-f496ca5/frontend/src/credential-accept/app.ts :284
const response = await deps.fetch(`/api/v1${endpoint}`, { - net ChronoAIProject-NyxID-f496ca5/frontend/src/features/blog/mock-api.ts :9
// Before going to production, replace these helpers with real `fetch()` calls - net (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/features/docs/docs-page.tsx :74
fetch(`/docs/${slug}.md`, { cache: "no-store" }) - net (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/features/docs/docs-search.tsx :37
fetch("/docs/search-index.json") - net ChronoAIProject-NyxID-f496ca5/frontend/src/lib/api-client.ts :138
const response = await fetch( - net ChronoAIProject-NyxID-f496ca5/frontend/src/lib/assistant/assistant-http.ts :211
(await fetch(apiUrl(endpoint, options.apiBaseUrl), init)); - net ChronoAIProject-NyxID-f496ca5/frontend/src/lib/assistant/direct-transport.ts :406
this.fetchFn = options.fetch ?? ((input, init) => fetch(input, init)); - net (weak) ChronoAIProject-NyxID-f496ca5/frontend/src/lib/proxy-probe.test.ts :455
it("forwards the AbortController signal to fetch (regression fence for timeout wiring)", async () => {
show 7 more
- net ChronoAIProject-NyxID-f496ca5/frontend/src/pages/_legal-document-page.tsx :46
fetch(mdPath, { cache: "no-store" }) - net (weak) ChronoAIProject-NyxID-f496ca5/frontend/vite.config.ts :61
// `fetch()` at runtime — the same copy-to-public pattern `public/legal/` - net (weak) ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/session.browser.test.mjs :6
import { createServer } from "node:http"; - net ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/worker.mjs :44
import { isIP } from "node:net"; - net ChronoAIProject-NyxID-f496ca5/mobile/src/features/legal/LegalDocumentScreen.tsx :65
fetch(url, { cache: "no-store" }) - net ChronoAIProject-NyxID-f496ca5/mobile/src/hooks/useNetworkStatus.ts :17
const state = await NetInfo.fetch(); - net ChronoAIProject-NyxID-f496ca5/mobile/src/lib/api/http.ts :401
const response = await fetch(buildUrl("/auth/refresh"), {
secrets 1
- secrets ChronoAIProject-NyxID-f496ca5/integrations/oracle/cdp-worker/worker.mjs :57
return process.env.NYXID_WORKER_TOKEN || "";
install hooks 2
- prepublishOnly ChronoAIProject-NyxID-f496ca5/sdk/oauth-core/package.json :23
npm run clean && npm run build - prepublishOnly ChronoAIProject-NyxID-f496ca5/sdk/oauth-react/package.json :22
npm run clean && npm run build
declared dependencies 82
- @hookform/resolvers@^5.2.2
- @noble/ciphers@^2.2.0
- @noble/curves@^2.2.0
- @noble/hashes@^2.2.0
- @radix-ui/react-avatar@^1.1.11
- @radix-ui/react-checkbox@^1.3.3
- @radix-ui/react-dialog@^1.1.15
- @radix-ui/react-dropdown-menu@^2.1.16
- @radix-ui/react-label@^2.1.8
- @radix-ui/react-popover@^1.1.15
- @radix-ui/react-select@^2.2.6
- @radix-ui/react-separator@^1.1.8
show 28 more
- @radix-ui/react-slot@^1.2.4
- @radix-ui/react-switch@^1.2.6
- @radix-ui/react-tabs@^1.1.13
- @radix-ui/react-tooltip@^1.2.8
- @tanstack/react-query@^5.90.20
- @tanstack/react-router@^1.159.5
- @xterm/addon-fit@^0.11.0
- @xterm/addon-webgl@^0.19.0
- @xterm/xterm@^6.0.0
- class-variance-authority@^0.7.1
- clsx@^2.1.1
- cmdk@^1.1.1
- i18next@^26.0.3
- lucide-react@^0.563.0
- posthog-js@^1.280.1
- qrcode@^1.5.4
- react@^19.2.4
- react-dom@^19.2.4
- react-hook-form@^7.71.1
- react-i18next@^17.0.2
- react-markdown@^10.1.0
- recharts@^3.8.1
- rehype-sanitize@^6.0.0
- rehype-slug@^6.0.0
- remark-directive@^4.0.0
- remark-gfm@^4.0.1
- sonner@^2.0.7
- tailwind-merge@^3.4.0
42 more not shown — this panel samples each group; the count above is the real total.