Close Open Privacy Scan
App Privacy Score
High risk · 694 finding(s)
Based on: 2 first-party package(s) · 53/56 deps analyzed
Dependency score: 57 (Medium risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Confirmed data exfiltration in application code
External domains:
ai.google.devaistudio.google.comapi.anthropic.comapi.arcee.aiapi.cerebras.aiapi.cohere.aiapi.deepgram.comapi.deepseek.comapi.elevenlabs.ioapi.empiriolabs.aiapi.fireworks.aiapi.groq.comapi.kimi.comapi.llmapi.aiapi.minimax.ioapi.mistral.aiapi.moonshot.aiapi.novita.aiapi.openai.comapi.perplexity.aiapi.sakana.aiapi.together.xyzapi.x.aiapi.z.aiapp.posthog.comarxiv.orgaws.amazon.comazure.microsoft.combailian.console.alibabacloud.combig-agi.comcdn.jsdelivr.netcdn.tailwindcss.comchutes.aicloud.cerebras.aiconsole.anthropic.comconsole.aws.amazon.comconsole.cloud.google.comconsole.groq.comconsole.mistral.aiconsole.sakana.aiconsole.x.aidashboard.cohere.comdashscope-intl.aliyuncs.comdeveloper.mozilla.orgdevelopers.cloudflare.comdevelopers.google.comdiscord.comdiscord.ggdocs.arcee.aidocs.claude.comdocs.empiriolabs.aidocs.fireworks.aidocs.perplexity.aien.wikipedia.orgf.vimeocdn.comform.typeform.comgateway.ai.cloudflare.comgenerativelanguage.googleapis.comgithub.comgoo.gli.giphy.comi.ytimg.cominworld.aijson-schema.orglearn.microsoft.comllm.chutes.aillmapi.ailmstudio.ailocalai.iomermaid.js.orgnextjs.orgnominatim.openstreetmap.orgnovita.ainpmjs.comollama.aiopenai.comopenrouter.aiplatform.deepseek.complatform.minimax.ioplatform.moonshot.aiplatform.openai.complayer.vimeo.composthog.compptr.devprogrammablesearchengine.google.compurl.oclc.orgreact-resizable-panels-au2wmqbbr-brian-vaughns-projects.vercel.appreact-resizable-panels-ca7gk2gh5-brian-vaughns-projects.vercel.appreact-resizable-panels.vercel.appreact-virtualized-auto-sizer.vercel.appreact.devreactjs.orgschema.orgschemas.microsoft.comschemas.openxmlformats.orgschemas.zwobble.orgsentry.iosharp.pixelplumbing.comstatus.anthropic.comstatus.openai.comtanstack.comtrpc.ious.i.posthog.comus.posthog.comvertexaisearch.cloud.google.comvimeo.comwebplatform.github.iowww.alibabacloud.comwww.anthropic.comwww.enricoros.comwww.google.comwww.googleapis.comwww.googletagmanager.comwww.kimi.comwww.mozilla.orgwww.perplexity.aiwww.plantuml.comwww.tokenfabrics.comwww.w3.orgwww.youtube-nocookie.comwww.youtube.comx.comyour-resource.openai.azure.comz.ai
- 1source
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75 - 2sink
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:86
- 1source
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51 - 2sink
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:76
- 1source
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:75 - 2sink
repo/src/modules/asrx/protocols/batch/transcribe-deepgram.ts:88
- 1source
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:51 - 2sink
repo/src/modules/asrx/protocols/batch/transcribe-openai.ts:78
- 1source
repo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/bserial2.mjs:2
- 1source
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:3 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
- 1source
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/pcheck.mjs:8
- 1source
repo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/probes2.mjs:6
- 1source
repo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/r3clean.mjs:3
- 1source
repo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/retention.mjs:12
- 1source
repo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11 - 2sink
repo/tools/develop/aix-anthropic-eviscerate/tokacct.mjs:11
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:119
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:122
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:91 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:123
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:259
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:260
- 1source
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:252 - 2sink
repo/tools/develop/aix-gemini-antigravity-probe/probe.ts:262
</> First-Party Code
first-party (npm)
npm first-party response = await fetch(url, {
method: 'POST',
headers,
body: new Blob([audio as BlobPart], { type: mimeType }),
signal,
});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
response = await fetch(url, {
method: 'POST',
headers,
body: formData,
signal,
});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
await posthogServerSendException(error, undefined, {
domain: 'trpc-onerror',
runtime: 'nodejs',
endpoint: path ?? 'unknown',
method: req.method,
url: req.url,
additionalProperties: {
error_code: error.code,
error_type: type,
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
import type { PostHog, Properties } from 'posthog-js';
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
headers,
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers,
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
import { PostHog } from 'posthog-node';
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
async function create(b) { const res = await fetch('https://api.anthropic.com/v1/messages', { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(b) }); return { status: res.status, body: await res.json() }; }
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
const r=await fetch('https://api.anthropic.com/v1/messages',{method:'POST',headers:{'x-api-key':apiKey(),'anthropic-version':'2023-06-01','content-type':'application/json'},body:JSON.stringify(b)});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
const r=await fetch('https://api.anthropic.com/v1/messages',{method:'POST',headers:{'x-api-key':apiKey(),'anthropic-version':'2023-06-01','content-type':'application/json'},body:JSON.stringify(b)});
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
const res = await fetch(url, { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
const res = await fetch('https://api.anthropic.com/v1/messages', { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' },
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
const res = await fetch(url, { method: 'POST', headers: { 'x-api-key': apiKey(), 'anthropic-version': '2023-06-01', 'content-type': 'application/json' }, body: JSON.stringify(body) });
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: { 'Content-Type': 'application/json', 'x-goog-api-key': API_KEY, 'Accept': 'text/event-stream' },
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
console.log('[capture] HTTP', res.status, res.headers.get('content-type'));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
if (!res.ok) { console.error(await res.text()); throw new Error(`HTTP ${res.status}`); }
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
const res = await fetch(url, { method: 'GET', headers: { 'x-goog-api-key': API_KEY } });
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
console.log('[get] HTTP', res.status, res.headers.get('content-type'));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
if (!res.ok) { console.error(text); throw new Error(`HTTP ${res.status}`); }
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 142 low-confidence finding(s)
low env_fs — Filesystem access. 44 locations
low env_fs — Environment-variable access. 73 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 17 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 8 locations
first-party (npm): tools/develop/gen-icon-sprites
npm first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Filesystem access. 5 locations
</> Dependencies
posthog-js
npm dependency posthog.setPersonPropertiesForFlags(personProperties);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
var replayUrl = posthog.get_session_replay_url();
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
if (!reportedSessionIds.has(sessionId)) {
updateCrispChat();
reportedSessionIds.add(sessionId);
}
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
var replayUrl = posthog.get_session_replay_url();
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
if (!reportedSessionIds.has(sessionId)) {
updateIntercom();
reportedSessionIds.add(sessionId);
}
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
if (args.length > 0 && !isCapturingLog && posthog.is_capturing()) {
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
if (!ctx.event.userId && ctx.event.anonymousId !== posthog.get_distinct_id()) {
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.reset();
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
if (ctx.event.userId && ctx.event.userId !== posthog.get_distinct_id()) {
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.identify(ctx.event.userId);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
var additionalProperties = posthog.calculateEventProperties(eventName, ctx.event.properties);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.register({
distinct_id: user.id(),
$device_id: getSegmentAnonymousId(),
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.capture(posthog_surveys_types_1.SurveyEventName.SHOWN, __assign(__assign((_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _a), (surveyLanguage && (_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _b))), { sessionRecordingUrl: (_c = posthog.get_session_replay_url) === null || _c === void 0 ? void 0 : _c.call(posthog) }));
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.capture(posthog_surveys_types_1.SurveyEventName.SENT, __assign(__assign(__assign(__assign(__assign((_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_SUBMISSION_ID] = surveySubmissionId, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_COMPLETED] = isSurveyCompleted, _b), (surveyLanguage && (_c = {}, _c[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _c))), { sessionRecordingUrl: (_e = posthog.get_session_replay_url) === null || _e === void 0 ? void 0 : _e.call(posthog) }), (0, surveys_1.buildSurveyResponseProperties)(responses, survey)), properties), { $set: (_d = {},
_d[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'responded')] = true,
_d) }));
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.reloadFeatureFlags();
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.capture(posthog_surveys_types_1.SurveyEventName.DISMISSED, __assign(__assign(__assign({}, _buildSurveyEventProperties(survey, inProgressSurvey, posthog)), (surveyLanguage && (_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _a))), { $set: (_b = {},
_b[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'dismissed')] = true,
_b) }));
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.capture(posthog_surveys_types_1.SurveyEventName.ABANDONED, _buildSurveyEventProperties(survey, inProgressSurvey, posthog), {
transport: 'sendBeacon',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog-node
npm dependency posthog.withContext(buildRequestContextData(posthog, req), () => next())
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.addPendingPromise(
ErrorTracking.buildEventMessage(
posthog.getErrorPropertiesBuilder(),
error,
hint,
contextData.distinctId,
additionalProperties
).then((msg) => {
return posthog._capturePreparedEvent(msg, false)
})
)
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
posthog.getErrorPropertiesBuilder(),
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
return posthog._capturePreparedEvent(msg, false)
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 2 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
@mui/joy
npm dependencyexpand_more 333 low-confidence finding(s)
low env_fs — Environment-variable access. 333 locations
@next/bundle-analyzer
npm dependencyexpand_more 1 low-confidence finding(s)
if (process.env.TURBOPACK) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
@tanstack/react-query
npm dependencyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
@trpc/client
npm dependencyexpand_more 1 low-confidence finding(s)
const requestSubscription = client
.request({
op,
transformer,
})
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
@trpc/next
npm dependencyexpand_more 1 low-confidence finding(s)
return fetch(url, {
...fetchOpts,
// cache: 'no-cache',
next: {
revalidate,
tags: [cacheTag],
},
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
aws4fetch
npm dependencyexpand_more 1 low-confidence finding(s)
const fetched = fetch(await this.sign(input, init))
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
idb-keyval
npm dependencyexpand_more 4 low-confidence finding(s)
mammoth
npm dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
nanoid
npm dependencyexpand_more 1 low-confidence finding(s)
let json = readFileSync(join(import.meta.dirname, '..', 'package.json'))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
pdfjs-dist
npm dependencyexpand_more 17 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 10 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 7 locations
puppeteer-core
npm dependencyexpand_more 47 low-confidence finding(s)
low env_fs — Filesystem access. 15 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 20 locations
low env_fs — Environment-variable access. 8 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
react
npm dependencyexpand_more 14 low-confidence finding(s)
low env_fs — Environment-variable access. 14 locations
react-dom
npm dependencyexpand_more 23 low-confidence finding(s)
low env_fs — Environment-variable access. 23 locations
react-hook-form
npm dependencyexpand_more 12 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
low env_fs — Filesystem access. 7 locations
const response = await fetch(String(action), {
method,
headers: {
...headers,
...(encType && encType !== 'multipart/form-data'
? { 'Content-Type': encType }
: {}),
},
body: shouldStringifySubmissionData ? formDataJson : formData,
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
react-resizable-panels
npm dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
react-timeago
npm dependencyexpand_more 6 low-confidence finding(s)
process.env['ES6'] ? null : '@babel/env',
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tesseract.js
npm dependencyexpand_more 20 low-confidence finding(s)
low env_fs — Filesystem access. 18 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
tiktoken
npm dependencyexpand_more 8 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
low env_fs — Filesystem access. 4 locations
zustand
npm dependencyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
Skipped dependencies
Production
- @prisma/client prod — tarball exceeds byte cap
- next prod — tarball exceeds byte cap
- superjson prod — dist-only: no readable source