Hi, this is Synabun. A little bit of this and a little bit of that. Have fun with it, hope it helps someone is some way.
- capability exposure inferred + 35
- tool safety inferred + 17
- trust mitigators mixed − 3
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 5m ago · see ecosystem CVEs →
No known CVEs for this server.
- high dangerous code
obfuscated payload: dynamic require()/import()
- medium toxic flow (lethal trifecta)
lethal trifecta reachable across this server's tools: private-data access + untrusted-content ingestion + network exfil
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/hooks/
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/hooks/
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/hooks/
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/hooks/
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/hooks/
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/mcp-se
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/mcp-se
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/preuni
- low dangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (danilokhury-Synabun-ebae7e8/preuni
analyzed commit ebae7e8 · analyzer v28 · 2d ago
skills & prompt files 2
danger signals1
- suspicious endpoint discord.com danilokhury-Synabun-ebae7e8/mcp-server/src/tools/discord-webhook.ts :53
return text(`Created webhook "${wh.name}" (${wh.id}) in <#${wh.channel_id}>.\nToken: ${wh.token}\nURL: https://discord.com/api/webhooks/${wh.id}/${wh.token}`);
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of danilokhury.