Close Open Privacy Scan

bolt Snapshot: commit 153a96a
science engine v1.23
schedule 2026-07-28T12:23:58.431963+00:00

verified_user No application data leak found

No high-confidence exfiltration was found in application code.

smart_toy MCP server detected: mcp — detected in dependencies, not a safety judgment.

App Privacy Score

97 /100
Low privacy risk

Low risk · 53 finding(s)

Based on: 1 first-party package(s) · 3/3 deps analyzed

Dependency score: 82 (Low risk)

bar_chart Score Breakdown

env_fs −3

list Scan Summary

0 high 0 medium 53 low
First-party packages: 1
Dependency packages: 3
Ecosystem: python

swap_horiz External domains

colin-b.github.iodatatracker.ietf.orgdeveloper.mozilla.orgdeveloper.okta.comdocs.aws.amazon.comdocs.microsoft.comdocs.python.orggithub.comlogin.microsoftonline.commodelcontextprotocol.ioopenid.nets3.amazonaws.comserver.localsethmlarson.devtools.ietf.orgwakatime.com

</> First-Party Code

first-party (python)

python first-party
expand_more 3 low-confidence finding(s)

</> Dependencies

mcp

python dependency
expand_more 39 low-confidence finding(s)
low env_fs Environment-variable access. 16 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 6 locations
low env_fs Filesystem access. 15 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

uvicorn

python dependency