tanav.aiScanLeaderboardResearchBlogGet Started
Open appTry free scan →
Disclosed Findings

Findings We Disclosed, Not Just Found

Every named finding below was reported to the maintainer before it appeared publicly here. No repo is named on this page without going through that process first — the same rule applies to anything cited in pitch materials or the blog.

disclosedSignificant-Gravitas/AutoGPT184k★CHK-115
Credential access in 3 SKILL.md files
Skill files instructed reading local credential files as part of a documented task step — a runtime instruction, not a test fixture.
disclosedgarrytan/gstack71k★CHK-115 + CHK-089
--dangerously-skip-permissions + .env credential access
Runtime source disables the permission-confirmation gate by default and reads local .env values as part of the same flow.
disclosedscreenpipe/screenpipe19k★CHK-027
Telegram data exfiltration instruction in SKILL.md
A skill instructs forwarding captured data to an external Telegram endpoint — an outbound exfil pattern, not an inbound fetch.

Disclosure Policy

Named findings are reported to the maintainer at least 7 days before publication. Evidence is redacted in public reports — full detail is available to the maintainer on request. A finding is only named here after that process completes, regardless of how confident the initial detection was.