Your brain, then your team's brain, then your agents' brain. Drop in documents and it compounds them into an interlinked markdown wiki you own — readable in Obsidian, synced through your own private GitHub repo. Share it with a cohort. Coding agents resume from it across sessions, models and machines.
- capability exposure inferred + 35
- recent drift inferred + 20
- tool safety inferred + 24
- trust mitigators mixed − 3
inferred mixed
The A–E grade is our heuristic synthesis — a "review this" prompt, not a verdict. Each factor is tagged by what backs it: attested (a verifiable record), reported (a third party's claim), or inferred (our own heuristic, e.g. permissions). See methodology.
grade last moved 1w ago · see ecosystem CVEs →
- D · 68 → D · 76
- C · 44 → D · 68
No known CVEs for this server.
- high dangerous code
committed secret: GitHub fine-grained PAT, GitHub token, private key · dynamic exec: new Function() · obfuscated payload: dynamic require()/import()
- high hidden prompt content
1 file(s) with hidden prompt content: talirezun-the-curator-4479596/CLAUDE.md (skill-exfil): "secret→sink: - **Server binds to 127.0.0.1 only (v3.0.1-beta.20+)** — `app.listen(POR…
analyzed commit 4479596 · analyzer v33 · 28m ago
skills & prompt files 3
- hidden: agent-rules: skill-exfil talirezun-the-curator-4479596/CLAUDE.md :628
secret→sink: - **Server binds to 127.0.0.1 only (v3.0.1-beta.20+)** — `app.listen(PORT, '127.0.0.1', ...)`. The Curator is a single-user localhost app; binding to all interfaces (the pre-beta.20 defau
danger signals89
- dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-agent-instructions.js :231
return new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-api-keys-contract.js :285
R = new Function(...names, body)(...names.map((n) => INJECTED[n])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-beta16-broken-links.js :748
return new Function('__calls', preamble + nextBodies.join('\n\n') + '\n' + api)(calls).__attach === undefined - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-chat-model.js :2606
const clientTitleFromSlug = new Function('slug', tfsMatch[1]); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-diagnostics.js :140
return new Function(...m.injected, body); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-health-cost-readouts.js :90
return new Function(...injectedNames, combined)(...injectedNames.map((k) => inject[k])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-health-merge-links.js :919
splitWikiRef = new Function(src + '\nreturn splitWikiRef;')(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-install-mode.js :719
const make = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-mcp-launcher.js :180
return new Function('MCP_SERVER_PATH', 'process', 'getCapabilities', 'getMcpLauncherPath', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-memory-truth.js :488
const escapeHtml = new Function(extractFunction( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-model-failure-ux.js :286
const delayFor = new Function('rateLimited', 'attempt', 'err', 'parseRetryDelay', 'MAX_RETRY_SLEEP_MS', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-cancel.js :293
const api = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-compile.js :195
return new Function(src)(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-filter.js :226
const api = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-scopebar.js :189
const api = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-sidebar.js :191
return new Function('__state', src); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-streaming.js :124
const realChipFn = (name) => new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-chat-waiting.js :140
const formatDurationMs = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-checkbox-visual.js :251
const resolve = (new Function('return ' + resolverSrc))()(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-compile-estimate.js :371
const buildOutSandbox = (body) => new Function(` - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-composer-model.js :375
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-confirm-dialog.js :428
const factory = new Function('document', 'Promise', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-cost-honesty.js :215
domainsSandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-design-kit.js :976
const make = new Function('state', 'escapeHtml', src.slice(start, fnEnd) + '\nreturn renderBackgroundMode;'); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domain-card-order.js :197
main = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domain-dots.js :406
domainDotClass = new Function(`const DOMAIN_DOT_SLOTS = ${slotCount};\n${fnSrc}\nreturn domainDotClass;`)(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domain-lifecycle.js :151
sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domain-pages.js :292
box = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domain-projects.js :198
sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domains-swr.js :199
box = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-domains-text.js :190
return new Function(...names, `${body}\nreturn ${returnName};`); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-existing-knowledge-folder.js :300
sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-icons.js :160
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-ingest-dropzone.js :432
const factory = new Function(...names, stripped + - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-ingest-view.js :188
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-invite-and-inert.js :189
const sharedApi = new Function(` - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-listbox.js :135
const escapeHtml = new Function(extractFunction(appJs, 'escapeHtml', 'app.js') + '\nreturn escapeHtml;')(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-loading-gate.js :542
const fn = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-markdown.js :279
const sandbox = new Function('icon', `${bodySrc}\nreturn { ${FNS.join(', ')} };`)(iconStub); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-mcp-wizard.js :191
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-memory-ingest-text.js :278
return new Function('state', 'escapeHtml', 'icon', 'renderMarkdown', 'gatedLoader', 'loadGate', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-memory-switch.js :173
const api = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-memory-view.js :851
const escapeHtml = new Function(extractFunction(appSrc, 'escapeHtml', 'app.js') + '\nreturn escapeHtml;')(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-model-fallback.js :162
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-model-gone-ui.js :193
S = new Function(...names, body)(...names.map((n) => SET_INJECTED[n])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-model-picker.js :866
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-onboarding.js :198
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-progress-ring.js :207
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-provider-rows.js :538
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-providers-page.js :195
R = new Function(...names, body)(...names.map((n) => INJECTED[n])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-raw-source.js :166
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-reader-motion.js :331
const factory = new Function('document', 'getComputedStyle', 'setTimeout', 'console', 'log', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-recovery-and-badge.js :224
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-semantic-gate.js :255
sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-settings-default-section.js :77
const SETTINGS_SECTIONS = SECTIONS_SRC ? new Function(SECTIONS_SRC[0] + '\nreturn SETTINGS_SECTIONS;')() : null; - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-settings-render-cost.js :122
return new Function(...keys, body)(...keys.map((k) => deps[k])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-settings-scroll-and-scale.js :209
const preserveFn = new Function('document', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-settings-sections.js :236
const fn = new Function(...names, [REAL, extractFunction(src, name), `return ${name};`].join('\n')); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-sharedbrain-admin.js :177
const sandbox = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-sharedbrain-ui-parity.js :172
const sharedBox = new Function('renderDescription', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-sharedbrain-wizard.js :110
try { new Function(out); } catch (e) { throw new Error(`extractFunction: "${name}" does not parse (${e.message})`); } - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-shell-rail.js :197
sandbox = new Function('__env', ` - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-sync-badge-invalidation.js :211
const factory = new Function('document', 'window', 'refreshSyncBadge', 'refreshSyncRemoteBadge', body); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-sync-spin.js :158
const sandbox = new Function(sandboxSrc)(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-text-system.js :148
const appEscape = new Function(src + '; return escapeHtml;')(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-title-affordances.js :240
const fn = new Function('escapeHtml', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-ui-polish.js :192
const factory = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-next-view-enter-motion.js :182
const factory = new Function('document', `${prelude}\n${fnSrc}\nreturn playViewEnter;`); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-offerable-models-route.js :855
const handler = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-openrouter-qualify.js :645
ui = new Function('escapeHtml', 'formatIsoDay', 'formatUsdHonest', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-save-kind.js :350
const escapeHtml = new Function(extractFunction( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-shared-block.js :130
const legacyBlock = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-sidebar-status-rows.js :561
const make = new Function('formatDayAge', 'freshnessDotHtml', 'clockGlyph', - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-sync-hygiene.js :1542
const view = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-sync-prune-safety.js :769
const view = new Function( - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-tray-shell.js :234
appFormatAge = new Function(`${body}\nreturn formatAge;`)(); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-ui-state.js :545
const mk = (durable) => new Function('durableStorage', 'localStorage', [ - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-update-in-app.js :286
return new Function(...FREE_NAMES, `${body}; return updateHandler;`)(...FREE_NAMES.map(n => env[n])); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-update-installer.js :222
const make = new Function(...CONFIG_EXPORT_NAMES, `${fnSrc}; return compareSemver;`); - dynamic code execution new Function() talirezun-the-curator-4479596/scripts/test-visual-contrast-math.js :192
const factory = new Function('location', 'window', 'document', `return (${fn.toString()});`); - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/.githooks/secret-allowlist :1
github…(39 chars, redacted) - committed secret GitHub token talirezun-the-curator-4479596/.githooks/secret-allowlist :10
ghp_th…(41 chars, redacted) - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/scripts/test-logger.js :239
github…(38 chars, redacted) - committed secret private key talirezun-the-curator-4479596/scripts/test-logger.js :243
PEM private key block (redacted) - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/scripts/test-sharedbrain-github-offline.js :612
github…(39 chars, redacted) - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/scripts/test-sharedbrain-local.js :367
github…(35 chars, redacted) - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/scripts/test-sharedbrain-revoke.js :1119
github…(38 chars, redacted) - committed secret GitHub fine-grained PAT talirezun-the-curator-4479596/scripts/test-sharedbrain-scenarios.js :188
github…(43 chars, redacted) - committed secret GitHub token talirezun-the-curator-4479596/scripts/test-sharedbrain-security.js :291
ghp_th…(41 chars, redacted)
- recent drift +20 capability drift →
Heuristic, inferred signals — false positives (legitimately powerful tools, forks, language ports) are expected. Treat each as "review this", not a verdict. See the ecosystem-wide picture on the security hub, or the fleet security of talirezun.