Close Open Privacy Scan

bolt Snapshot: commit 55679f5
science engine v1.23
schedule 2026-07-27T09:15:43.261355+00:00

verified_user No application data leak found

No high-confidence exfiltration was found in application code. Dependency data flows are listed separately and do not affect this verdict.

App Privacy Score

97 /100
Low privacy risk

Low risk · 296 finding(s)

Based on: 1 first-party package(s) · 2/2 deps analyzed

Dependency score: 52 (Medium risk)

bar_chart Score Breakdown

env_fs −3

list Scan Summary

1 high 0 medium 295 low
First-party packages: 1
Dependency packages: 2
Ecosystem: npm

swap_horiz Application data flows

No application data flows were found. See dependency data flows below.

hub Dependency data flows (1)
high playwright dependency User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/transform/esmLoader.js:8020
  2. 2sinkpkgs/npm/[email protected]/lib/transform/esmLoader.js:8023

</> First-Party Code

</> Dependencies

playwright

npm dependency
high pii_flow dependency Excluded from app score #fb0691c72e3428a0 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
pkgs/npm/[email protected]/lib/transform/esmLoader.js:8023 · flow /tmp/closeopen-dukr54fc/pkgs/npm/[email protected]/lib/transform/esmLoader.js:8020 → /tmp/closeopen-dukr54fc/pkgs/npm/[email protected]/lib/transform/esmLoader.js:8023
    transport?.post("pushToCompilationCache", { cache: transformed.serializedCache });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

expand_more 229 low-confidence finding(s)
low env_fs Filesystem access. 112 locations
low env_fs Environment-variable access. 117 locations

playwright-core

npm dependency
expand_more 52 low-confidence finding(s)
low env_fs Environment-variable access. 26 locations
low env_fs Filesystem access. 18 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 8 locations