Close Open Privacy Scan

bolt Snapshot: commit 072cd2f
science engine v1.23
schedule 2026-07-25T08:12:08.753483+00:00

verified_user Application data leak confirmed

High-confidence data exfiltration identified in application code.

App Privacy Score

0 /100
High privacy risk — application leak confirmed

High risk · 694 finding(s)

Based on: 2 first-party package(s) · 53/56 deps analyzed

Dependency score: 57 (Medium risk)

bar_chart Score Breakdown

pii_flow −60
telemetry −25
egress −15
env_fs −3

list Scan Summary

2 high 41 medium 651 low
First-party packages: 2
Dependency packages: 21
Ecosystem: npm

swap_horiz Confirmed data exfiltration in application code

External domains: ai.google.devaistudio.google.comapi.anthropic.comapi.arcee.aiapi.cerebras.aiapi.cohere.aiapi.deepgram.comapi.deepseek.comapi.elevenlabs.ioapi.empiriolabs.aiapi.fireworks.aiapi.groq.comapi.kimi.comapi.llmapi.aiapi.minimax.ioapi.mistral.aiapi.moonshot.aiapi.novita.aiapi.openai.comapi.perplexity.aiapi.sakana.aiapi.together.xyzapi.x.aiapi.z.aiapp.posthog.comarxiv.orgaws.amazon.comazure.microsoft.combailian.console.alibabacloud.combig-agi.comcdn.jsdelivr.netcdn.tailwindcss.comchutes.aicloud.cerebras.aiconsole.anthropic.comconsole.aws.amazon.comconsole.cloud.google.comconsole.groq.comconsole.mistral.aiconsole.sakana.aiconsole.x.aidashboard.cohere.comdashscope-intl.aliyuncs.comdeveloper.mozilla.orgdevelopers.cloudflare.comdevelopers.google.comdiscord.comdiscord.ggdocs.arcee.aidocs.claude.comdocs.empiriolabs.aidocs.fireworks.aidocs.perplexity.aien.wikipedia.orgf.vimeocdn.comform.typeform.comgateway.ai.cloudflare.comgenerativelanguage.googleapis.comgithub.comgoo.gli.giphy.comi.ytimg.cominworld.aijson-schema.orglearn.microsoft.comllm.chutes.aillmapi.ailmstudio.ailocalai.iomermaid.js.orgnextjs.orgnominatim.openstreetmap.orgnovita.ainpmjs.comollama.aiopenai.comopenrouter.aiplatform.deepseek.complatform.minimax.ioplatform.moonshot.aiplatform.openai.complayer.vimeo.composthog.compptr.devprogrammablesearchengine.google.compurl.oclc.orgreact-resizable-panels-au2wmqbbr-brian-vaughns-projects.vercel.appreact-resizable-panels-ca7gk2gh5-brian-vaughns-projects.vercel.appreact-resizable-panels.vercel.appreact-virtualized-auto-sizer.vercel.appreact.devreactjs.orgschema.orgschemas.microsoft.comschemas.openxmlformats.orgschemas.zwobble.orgsentry.iosharp.pixelplumbing.comstatus.anthropic.comstatus.openai.comtanstack.comtrpc.ious.i.posthog.comus.posthog.comvertexaisearch.cloud.google.comvimeo.comwebplatform.github.iowww.alibabacloud.comwww.anthropic.comwww.enricoros.comwww.google.comwww.googleapis.comwww.googletagmanager.comwww.kimi.comwww.mozilla.orgwww.perplexity.aiwww.plantuml.comwww.tokenfabrics.comwww.w3.orgwww.youtube-nocookie.comwww.youtube.comx.comyour-resource.openai.azure.comz.ai

high first-party (npm) A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75
  2. 2sinkrepo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:86
high first-party (npm) A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51
  2. 2sinkrepo/src/modules/asrx/protocols/batch/transcribe-openai.ts:76
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75
  2. 2sinkrepo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:88
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51
  2. 2sinkrepo/src/modules/asrx/protocols/batch/transcribe-openai.ts:78
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2
medium first-party (npm) User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration. Destination is a known provider host — credential-to-issuer flow, not exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:3
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11
  2. 2sinkrepo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:119
medium first-party (npm) PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:122
medium first-party (npm) PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:123
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:259
medium first-party (npm) PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:260
medium first-party (npm) PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcerepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252
  2. 2sinkrepo/tools/develop/aix-gemini-antigravity-probe/probe.ts:262

</> First-Party Code

first-party (npm)

npm first-party
high pii_flow production #33fbf68a6410b318 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:86 · flow /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75 → /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:86
    response = await fetch(url, {
      method: 'POST',
      headers,
      body: new Blob([audio as BlobPart], { type: mimeType }),
      signal,
    });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #eb2e655aef375d85 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:76 · flow /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51 → /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:76
    response = await fetch(url, {
      method: 'POST',
      headers,
      body: formData,
      signal,
    });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium telemetry production #b47d537fdafde7bd capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/app/api/cloud/[trpc]/route.ts:19
    await posthogServerSendException(error, undefined, {
      domain: 'trpc-onerror',
      runtime: 'nodejs',
      endpoint: path ?? 'unknown',
      method: req.method,
      url: req.url,
      additionalProperties: {
        error_code: error.code,
        error_type: type,
      },
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #25fcbcb472a6772e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/common/components/3rdparty/PostHogAnalytics.tsx:2
import type { PostHog, Properties } from 'posthog-js';

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow production #50578fab27084195 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:88 · flow /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75 → /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:88
      headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #69236d93cd3bb7ba A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:78 · flow /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51 → /tmp/closeopen-e4ap0uz9/repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:78
      headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium telemetry production #e646908060ba1909 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/server/posthog/posthog.server.ts:9
import { PostHog } from 'posthog-node';

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow production #549ac4f9425f888e A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2
async function create(b) { const res = await fetch('https://api.anthropic.com/v1/messages', { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(b) }); return { status: res.status, body: await res.json() }; }

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #25bfa1894655c9eb User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration. Destination is a known provider host — credential-to-issuer flow, not exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:3 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
  const r=await fetch('https://api.anthropic.com/v1/messages',{method:'POST',headers:{'x-api-key':apiKey(),'anthropic-version':'2023-06-01','content-type':'application/json'},body:JSON.stringify(b)});

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium pii_flow production #e281a75f2ca64649 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
  const r=await fetch('https://api.anthropic.com/v1/messages',{method:'POST',headers:{'x-api-key':apiKey(),'anthropic-version':'2023-06-01','content-type':'application/json'},body:JSON.stringify(b)});

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #3cb98b462c6c14e1 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6
  const res = await fetch(url, { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #520a6555a90d7317 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3
  const res = await fetch('https://api.anthropic.com/v1/messages', { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #77bb03d6788181b3 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12
    headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #f686f5444846c6b3 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11
  const res = await fetch(url, { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #a0673f6f1b8e231f A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:119 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:119
    headers: { 'Content-Type': 'application/json', 'x-goog-api-key': API_KEY, 'Accept': 'text/event-stream' },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #eae6c16adb1c9701 PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:122 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:122
  console.log('[capture] HTTP', res.status, res.headers.get('content-type'));

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #dd879053d2f13063 PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:123 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:123
  if (!res.ok) { console.error(await res.text()); throw new Error(`HTTP ${res.status}`); }

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #45cc12dcc2a1a293 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:259 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:259
  const res = await fetch(url, { method: 'GET', headers: { 'x-goog-api-key': API_KEY } });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #2ebb80f9d0166216 PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:260 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:260
  console.log('[get] HTTP', res.status, res.headers.get('content-type'));

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #35eb6f9ccf81a577 PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process.
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:262 · flow /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 → /tmp/closeopen-e4ap0uz9/repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:262
  if (!res.ok) { console.error(text); throw new Error(`HTTP ${res.status}`); }

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

expand_more 142 low-confidence finding(s)
low env_fs Filesystem access. 44 locations
low env_fs Environment-variable access. 73 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 17 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 8 locations

</> Dependencies

posthog-js

npm dependency
medium telemetry dependency Excluded from app score #575222789a5baa35 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/customizations/setAllPersonProfilePropertiesAsPersonPropertiesForFlags.js:17
    posthog.setPersonPropertiesForFlags(personProperties);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #a892eb8ed3f62b48 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:22
            var replayUrl = posthog.get_session_replay_url();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #adeb82762a3242cd capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:23
            var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #450a0f6603cbda30 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:37
        sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
            if (!reportedSessionIds.has(sessionId)) {
                updateCrispChat();
                reportedSessionIds.add(sessionId);
            }
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #9a629dc8df9e848d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:22
            var replayUrl = posthog.get_session_replay_url();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #ba49c5d91272a3d7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:23
            var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #940eaac8a2f56fc8 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:32
        sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
            if (!reportedSessionIds.has(sessionId)) {
                updateIntercom();
                reportedSessionIds.add(sessionId);
            }
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #38eecba5776a273f capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/logs.js:341
                    if (args.length > 0 && !isCapturingLog && posthog.is_capturing()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #35be8fb444757d73 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:17
        if (!ctx.event.userId && ctx.event.anonymousId !== posthog.get_distinct_id()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #b9541d4671c1fcdc capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:20
            posthog.reset();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #4652341cf1b27ec1 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:22
        if (ctx.event.userId && ctx.event.userId !== posthog.get_distinct_id()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #e16990721b21f0e6 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:24
            posthog.identify(ctx.event.userId);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #234cc74fdea82fbb capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:26
        var additionalProperties = posthog.calculateEventProperties(eventName, ctx.event.properties);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #3a2193d3b80f6103 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:55
            posthog.register({
                distinct_id: user.id(),
                $device_id: getSegmentAnonymousId(),
            });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #afdb807fd7a5a437 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys.js:896
                posthog.capture(posthog_surveys_types_1.SurveyEventName.SHOWN, __assign(__assign((_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _a), (surveyLanguage && (_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _b))), { sessionRecordingUrl: (_c = posthog.get_session_replay_url) === null || _c === void 0 ? void 0 : _c.call(posthog) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #a3f3934f7a54f3d9 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:383
    posthog.capture(posthog_surveys_types_1.SurveyEventName.SENT, __assign(__assign(__assign(__assign(__assign((_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_SUBMISSION_ID] = surveySubmissionId, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_COMPLETED] = isSurveyCompleted, _b), (surveyLanguage && (_c = {}, _c[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _c))), { sessionRecordingUrl: (_e = posthog.get_session_replay_url) === null || _e === void 0 ? void 0 : _e.call(posthog) }), (0, surveys_1.buildSurveyResponseProperties)(responses, survey)), properties), { $set: (_d = {},
            _d[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'responded')] = true,
            _d) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #a75ffb3bebc7ab2f capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:393
        posthog.reloadFeatureFlags();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #d5fa397148771733 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:414
    posthog.capture(posthog_surveys_types_1.SurveyEventName.DISMISSED, __assign(__assign(__assign({}, _buildSurveyEventProperties(survey, inProgressSurvey, posthog)), (surveyLanguage && (_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _a))), { $set: (_b = {},
            _b[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'dismissed')] = true,
            _b) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #fd39096541f3b0b7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:447
    posthog.capture(posthog_surveys_types_1.SurveyEventName.ABANDONED, _buildSurveyEventProperties(survey, inProgressSurvey, posthog), {
        transport: 'sendBeacon',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

posthog-node

npm dependency
medium telemetry dependency Excluded from app score #ab98069f1f42ca15 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:69
    posthog.withContext(buildRequestContextData(posthog, req), () => next())

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #7fcfba5fcc6687b0 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:98
    posthog.addPendingPromise(
      ErrorTracking.buildEventMessage(
        posthog.getErrorPropertiesBuilder(),
        error,
        hint,
        contextData.distinctId,
        additionalProperties
      ).then((msg) => {
        return posthog._capturePreparedEvent(msg, false)
      })
    )

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #543b4c6f2e07bb00 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:100
        posthog.getErrorPropertiesBuilder(),

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #04ce941cff720a99 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:106
        return posthog._capturePreparedEvent(msg, false)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 2 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations

@mui/joy

npm dependency
expand_more 333 low-confidence finding(s)
low env_fs Environment-variable access. 333 locations

@next/bundle-analyzer

npm dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #9afa09d6c8775b33 capability detected · no path traced Environment-variable access.
pkgs/npm/@[email protected]/index.js:7
    if (process.env.TURBOPACK) {

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

@trpc/client

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #e496b4adc938a36b capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]/src/links/wsLink/wsLink.ts:40
        const requestSubscription = client
          .request({
            op,
            transformer,
          })

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

@trpc/next

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #b7ec35add3c411cb capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]/src/app-dir/links/nextHttp.ts:52
        return fetch(url, {
          ...fetchOpts,
          // cache: 'no-cache',
          next: {
            revalidate,
            tags: [cacheTag],
          },
        });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

aws4fetch

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #502369d3ea017f53 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/[email protected]__reposrc/src/main.js:113
      const fetched = fetch(await this.sign(input, init))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

mammoth

npm dependency
expand_more 3 low-confidence finding(s)

nanoid

npm dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #611c1a3d77b60857 capability detected · no path traced Filesystem access.
pkgs/npm/[email protected]/bin/nanoid.js:18
  let json = readFileSync(join(import.meta.dirname, '..', 'package.json'))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

pdfjs-dist

npm dependency
expand_more 17 low-confidence finding(s)

puppeteer-core

npm dependency
expand_more 47 low-confidence finding(s)
low env_fs Filesystem access. 15 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 20 locations
low env_fs Environment-variable access. 8 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations

react-hook-form

npm dependency
expand_more 12 low-confidence finding(s)
low env_fs Environment-variable access. 4 locations
low env_fs Filesystem access. 7 locations
low egress dependency Excluded from app score #96a8f939d396a901 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/[email protected]__reposrc/src/form.tsx:88
            const response = await fetch(String(action), {
              method,
              headers: {
                ...headers,
                ...(encType && encType !== 'multipart/form-data'
                  ? { 'Content-Type': encType }
                  : {}),
              },
              body: shouldStringifySubmissionData ? formDataJson : formData,
            });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

react-resizable-panels

npm dependency

react-timeago

npm dependency
expand_more 6 low-confidence finding(s)
low env_fs dependency Excluded from app score #c0dd9cda4939558a capability detected · no path traced Environment-variable access.
pkgs/npm/[email protected]/.babelrc.js:3
    process.env['ES6'] ? null : '@babel/env',

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Filesystem access. 5 locations

tiktoken

npm dependency
expand_more 8 low-confidence finding(s)

zustand

npm dependency
expand_more 2 low-confidence finding(s)

Skipped dependencies

Production

  • @prisma/client prod — tarball exceeds byte cap
  • next prod — tarball exceeds byte cap
  • superjson prod — dist-only: no readable source