Analyze stocks with summaries, price targets, and analyst recommendations. Track SEC filings, divi…
- capability exposureinferred+28
- recent driftinferred+20
- tool safetyinferred+12
- trust mitigatorsmixed−8
inferredmixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
graded 13m ago · see ecosystem CVEs →
- D · 64 → C · 52
No known CVEs for this server.
- highhidden prompt content
2 file(s) with hidden prompt content: hollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/new-app/SKILL.md (skill-exfil), hollaugo-tutorials-21cf4ff/prompt-circle-marketplace/pl…
- lowdangerous code
env-secret-flows-to-network-js: A process environment value (often a secret/token) flows into a network call — possible credential exfiltration. (/scratch/obs-code-tgfLGY/hollaugo-
analyzed commit 21cf4ff · analyzer v19 · 1d ago
skills & prompt files 20
- hidden: skill: skill-exfilhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/new-app/SKILL.md:166
secret→sink: const WIDGET_DOMAIN = process.env.WIDGET_DOMAIN || `http://localhost:${PORT}`; - hidden: skill: skill-exfilhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/new-app/SKILL.md:166
secret→sink: const WIDGET_DOMAIN = process.env.WIDGET_DOMAIN || `http://localhost:${PORT}`;
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/add-auth/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/add-database/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/add-tool/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/add-widget/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/deploy/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/golden-prompts/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/resume-app/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/test/SKILL.md
- skillhollaugo-tutorials-21cf4ff/chatgpt-apps-plugin/skills/validate/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/add-auth/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/add-database/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/add-tool/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/add-widget/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/deploy/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/golden-prompts/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/resume-app/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/test/SKILL.md
- skillhollaugo-tutorials-21cf4ff/prompt-circle-marketplace/plugins/chatgpt-apps-builder/skills/validate/SKILL.md
- recent drift+20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of hollaugo.