github.com / f
f/ prompts.chat
HTML·1535 files·commit d3e04f1·scanned 5d ago·cached ✓
15/100
LOW RISK
Minor findings consistent with the project type. Nothing reachable from install hooks.
score capped at 15 — 167,465+ stars — findings likely false positives
verdict accurate?
167,465 stars
8% file coverage
threat-state: lowlive
FINDINGS ░▒▓
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.packages/prompts.chat/src/variables/index.ts+3
warningHigh-entropy string literalsFound 10 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.scripts/setup.js+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.src/lib/plugins/widgets/index.ts+3
warningHigh-entropy string literalsFound 6 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.packages/prompts.chat/scripts/generate-docs.ts+3
warningFlattened or dead control flowDetected switch(true), dead if branches, or deeply nested ternaries — patterns used by obfuscators to hide execution order.packages/prompts.chat/scripts/generate-docs.ts+3
warningHigh-entropy string literalsFound 3 long strings with high Shannon entropy. This is common in obfuscated payloads that hide URLs, keys, or bytecode.packages/prompts.chat/src/builder/chat.ts+3
infoSuspicious file in repoVery large source file (770KB) — could contain obfuscated payloadpackage-lock.json+2
warningDependency runs install scripts"<root>/postinstall" executes code during installation. Malicious packages use this to drop payloads before the app even runs.package.json+3
Scores are heuristics. A “safe” verdict means no known-malicious patterns were found — clever malware can look boring. Wrong verdict? Flag it above; confirmed false positives become regression tests.
120 files scanned @ d3e04f1 | 8/19/2026 | heuristic scan — always review manually
risk by category
code execution2
network & exfiltration0
file system access0
obfuscation15
supply chain7
owasp / injection0
telemetry
files 120/1535rules hit 10engine v5commit d3e04f1
github
f/prompts.chat
f.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
167465
21619
1358d
1535 files
120 scanned(8%)
d3e04f1
architecture░▒▓
entry (0) flagged (11) pkg (81)
194 nodes · 376 edgesscroll to zoom · click node to jump to finding