github.com / daobataotie
daobataotie/ CAD-MCP
Python·15 files·commit bfcf9bb·scanned 1h ago·cached ✓
20/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
verdict accurate?
threat-state: lowlive
FINDINGS ░▒▓
warningHigh-entropy string literalsFound 25 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/cad_controller.py+3
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/nlp_processor.py+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/nlp_processor.py+3
warningHigh-entropy string literalsFound 21 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.src/server.py+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
7 files scanned @ bfcf9bb | 9/25/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation12
supply chain0
owasp / injection0
telemetry
files 7/15rules hit 5engine v6commit bfcf9bb
github
daobataotie/CAD-MCP
CAD MCP Server
565
82
550d
15 files
7 scanned(47%)
bfcf9bb
architecture░▒▓
entry (0) flagged (3) pkg (28)
34 nodes · 48 edgesscroll to zoom · click node to jump to finding