Close Open Privacy Scan
App Privacy Score
Medium risk · 117 finding(s)
Dependency score: 97 (Low risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz External domains
::ffff:192.168.0.1a.coaccess.line.meaccounts.google.comaccounts.spotify.comadaptivecards.ioaggregate.ee.engr.uky.eduai-sdk.devai.azure.comai.google.devaiplatform.googleapis.comaistudio.google.comanimations.devaomediacodec.github.ioapi-m.paypal.comapi-m.sandbox.paypal.comapi.anthropic.comapi.atlassian.comapi.botframework.azure.usapi.botframework.comapi.botframework.usapi.cerebras.aiapi.cloudflare.comapi.cohere.aiapi.cohere.comapi.deepseek.comapi.dropboxapi.comapi.figma.comapi.github.comapi.githubcopilot.comapi.groq.comapi.kick.comapi.line.meapi.linear.appapi.linkedin.comapi.minimax.ioapi.mistral.aiapi.notion.comapi.nuget.orgapi.openai.comapi.paypal.comapi.perplexity.aiapi.polar.shapi.sandbox.paypal.comapi.slack.comapi.spotify.comapi.telegram.orgapi.vercel.comapi.weixin.qq.comapi.x.aiapi.x.comapi.z.aiapi.zoom.usapis.roblox.comapp.asana.comapp.getoutline.comapp.posthog.comapp.slack.comappleid.apple.comapps.extensions.modelcontextprotocol.ioarchestra.aiassets.anthropic.comauth.atlassian.comauth.company.comauth.openai.comaws.amazon.combackboard.railway.combedrock-agent-runtime.us-west-2.amazonaws.combedrock-mantle.us-east-1.api.awsbedrock-runtime.us-east-1.amazonaws.combetter-auth.combotframework.azure.usbrotlipy.readthedocs.iobugreports.qt.iobugs.python.orgbugs.winehq.orgbugzilla.gnome.orgcdn.discordapp.comcdn.jsdelivr.netcdn.mathjax.orgcdn.playwright.devcdnjs.cloudflare.comcens.ioc.eechatgpt.comchromium.googlesource.comclick.palletsprojects.comcloud.cerebras.aicognitiveservices.azure.comcommonmark.orgconsole.anthropic.comconsole.aws.amazon.comconsole.groq.comconsole.mistral.aicrates.iocryptography.iodashboard.cohere.comdashboard.ngrok.comdata-apis.orgdatatracker.ietf.orgdate-fns.orgdev.mysql.comdeveloper.microsoft.comdeveloper.mozilla.orgdeveloper.salesforce.comdevelopers.cloudflare.comdevelopers.openai.comdigitalassets.lib.berkeley.edudiscord.comdiscord.ggdmlc.github.iodoc.rust-lang.orgdocbook.sourceforge.netdocs.anthropic.comdocs.aws.amazon.comdocs.claude.comdocs.cloud.google.comdocs.expo.devdocs.geldata.comdocs.npmjs.comdocs.pydantic.devdocs.pytest.orgdocs.python.orgdocs.rsdocs.scipy.orgdocs.vllm.aidocs.z.aidod-graph.microsoft.usdoi.orgdotenvx.come2e-tests-keycloak.default.svc.cluster.localedgeupdates.microsoft.comen.wikipedia.orgeu.i.posthog.comfastapi.tiangolo.comfastify.devfd00:ec2::254fonts.googleapis.comfoo.comform.typeform.comgcc.gnu.orggenerativelanguage.googleapis.comgist.github.comgithub.comgitlab.comgitlab.freedesktop.orggoo.glgoogle.aip.devgoogle.comgraph.facebook.comgraph.microsoft.comgraph.microsoft.degraph.microsoft.usgraphics.stanford.edugroups.google.comhandlebarsjs.comhelp.openai.comhelp.salesforce.comhost.docker.internalhtml.spec.whatwg.orghttpbin.orghttpwg.orghuggingface.coid.kick.comid.twitch.tvid.vk.comidp.company.comidp.paybin.ioimageio.readthedocs.ioipython.orgj3-fortran.orgjsforce.github.iojson-schema.orgjsonplaceholder.typicode.comkapi.kakao.comkauth.kakao.comkubernetes.iolegacy.reactjs.orglibsdl.orglimited.facebook.comlinear.applocal.drizzle.studiolocalhost.tiangolo.comlodash.comlogin.botframework.azure.uslogin.botframework.comlogin.microsoftonline.comlogin.microsoftonline.uslogin.salesforce.comm365.cloud.microsoftmanagement.azure.commathworld.wolfram.commatplotlib.orgmesonbuild.commetacpan.orgmicrosoft.commicrosoftgraph.chinacloudapi.cnmodelcontextprotocol.iomodels.devmüller.denicolas.limare.netnid.naver.comnpm.imnpms.ionumpy.orgnumpydoc.readthedocs.iooauth.reddit.comoauth2.googleapis.comollama.aiopen.bigmodel.cnopen.tiktokapis.comopen.weixin.qq.comopenapi.naver.comopenid.netopenidconnect.googleapis.comopenrouter.aiorigin.asdorm.drizzle.teamother.compackages.msys2.orgpandas.pydata.orgpeople.eecs.berkeley.edupeps.python.orgpersonal.math.ubc.caplatform.claude.complatform.deepseek.complatform.minimax.ioplatform.openai.complaywright.bloburlplaywright.download.prss.microsoft.compolar.shportal.azure.comportal.ssoportal.sso-fipsposthog.compurl.oclc.orgpyinstaller.readthedocs.iopyjwt.readthedocs.iopypi.orgraw.githubusercontent.comreact-native.canny.ioreact.devreactjs.orgrequests.readthedocs.ios3-fips.dualstacks3-fips.dualstack.us-east-1s3-fips.us-east-1s3.amazonaws.coms3.dualstacks3.dualstack.us-east-1schemas.microsoft.comschemas.openxmlformats.orgschemas.xmlsoap.orgschemas.zwobble.orgscikit-image.orgscipy-cookbook.readthedocs.ioscipy-lectures.orgsentry.iosethmlarson.devslack.comsoap.sforce.comsonner.emilkowal.skisourceware.orgspdx.devstackoverflow.comsts.amazonaws.comsts.windows.netstuk.github.iosupport.microsoft.comswagger.iot.metanstack.comteams.microsoft.comtest.salesforce.comtoken.botframework.comtools.ietf.orgtruststore.readthedocs.iotwitter.comtyper.tiangolo.comtyping.python.orgunpkg.comurllib3.readthedocs.ious.i.posthog.comus.posthog.comvercel.comviews.scientific-python.orgweb.archive.orgwebhook.sitewixtoolset.orgwrapdb.mesonbuild.comwww.ams.orgwww.apache.orgwww.botframework.comwww.dropbox.comwww.eclipse.orgwww.ecma-international.orgwww.facebook.comwww.figma.comwww.force.comwww.google.comwww.googleapis.comwww.iana.orgwww.intel.comwww.linkedin.comwww.math.hmc.eduwww.mathjax.orgwww.mathworks.comwww.minimax.iowww.npmjs.comwww.oasis-open.orgwww.openblas.netwww.paypal.comwww.perplexity.aiwww.pyopenssl.orgwww.python.orgwww.reddit.comwww.rfc-editor.orgwww.sandbox.paypal.comwww.scipy.orgwww.sqlite.orgwww.starlette.devwww.stixfonts.orgwww.tiktok.comwww.w3.orgwww.webmproject.orgwww.xyz.eduwww.youtube.comx.aix.comxn--fiqs8s.icom.museumyahoo.comyarnpkg.comyour-app.comyour-domain.atlassian.netyour-instance.service-now.comyour-tenant.sharepoint.comz.aizoom.us
</> First-Party Code
first-party (rust): ai-labs/analyzer
rust first-partyexpand_more 11 low-confidence finding(s)
std::fs::write(work.path().join("analyses.md"), analyses_doc)?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&md_path, &rollout.markdown)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
&rubrics_tmp,
rubrics_jsonl(analyzed.iter().map(|(_, _, record)| record)),
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&analyses_path, &analyses_doc)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&out_path, &report.text).wrap_err_with(|| format!("writing report to {}", out_path.display()))?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(dir.join("run.json"), run_json).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
dir.join("trajectory.jsonl"),
"{\"kind\":\"assistant_text\",\"text\":\"hi\"}\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::read_to_string(&path).wrap_err_with(|| format!("reading required run.json at {}", path.display()))?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let mut f = std::fs::File::create(dir.path().join("run.json")).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let content = std::fs::read_to_string(path).map_err(|e| LoadError {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let mut f = std::fs::File::create(&path).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (rust): ai-labs/cli
rust first-partyexpand_more 2 low-confidence finding(s)
tracing::error!("benchmark failed: {e}");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::error!("benchmark failed: {e}");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
first-party (rust): ai-labs/core
rust first-partyexpand_more 2 low-confidence finding(s)
let content = std::fs::read_to_string(path).map_err(|e| LaneError(format!("{ctx}: {e}")))?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(dir.path().join("lanes.toml"), body).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (rust): ai-labs/dashboard
rust first-partyexpand_more 7 low-confidence finding(s)
tracing::error!("handler error: {err:#}");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::info!(
"dashboard listening on http://{addr} (experiments dir: {})",
cfg.experiments_dir.display()
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
match std::fs::read_to_string(&path) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let bytes = std::fs::read(path).ok()?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let meta: RunMeta = match std::fs::read(&path)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let text = match std::fs::read_to_string(&path) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
Ok(_) => match std::fs::read_to_string(&path) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (rust): ai-labs/runner
rust first-partyexpand_more 49 low-confidence finding(s)
std::env::var("GITHUB_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
.or_else(|_| std::env::var("GH_TOKEN"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(tmp.join(format!("{id}.toml")), content).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
d.join("task.toml"),
"[[stages]]\ntext = \"go\"\n[result_schema]\ntype = \"object\"\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(d.join("verifier.py"), "def test_ok(): assert True\n").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&path, content).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
envs_dir.join("isolated.toml"),
"id = \"isolated\"\nname = \"isolated\"\ntasks = [\"t1\"]\nfixture_mcp = true\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
envs_dir.join("shared.toml"),
"id = \"shared\"\nname = \"shared\"\ntasks = [\"t2\"]\nfixture_mcp = true\nshare_backend = true\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
match std::fs::read_to_string(&target) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(dir.join("verifier.py"), "def test_ok(): assert True\n").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
dir.join("task.toml"),
format!("{stages_toml}\n[result_schema]\ntype = \"object\"\n"),
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let text = std::fs::read_to_string(path)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let txt = std::fs::read_to_string(&path).unwrap_or_else(|e| panic!("read {path}: {e}"));
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let log_file = std::fs::File::create(&self.log_path)?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let text = std::fs::read_to_string(path)?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let mut combined = std::env::vars().collect::<HashMap<_, _>>();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let explicit = std::env::var("ARCHESTRA_BENCH_DATABASE_URL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let log_file = std::fs::File::create(&log_path)?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let contents = std::fs::read_to_string(compose_file).map_err(|e| {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let mut env: HashMap<String, String> = std::env::vars().collect();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
non_empty(std::env::var(key).ok())
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(repo_path.join("f.txt"), "x").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(
&path,
"# see registry.dagger.io/engine:<tag>\nservices:\n bench-dagger:\n image: registry.dagger.io/engine:v9.9.9 # pinned\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&path, "services:\n bench-dagger:\n image: postgres:18\n").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&path, "# comment\nFOO=bar\nBAZ=qux\n\nREF=$FOO/${BAZ}\n").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(&tmp, json).map_err(|e| format!("writing {}: {e}", tmp.display()))?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let bytes = match std::fs::read_to_string(&path) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
std::fs::write(dir.path().join("basic.mcp.lock"), "{ not json").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tracing::warn!(
requested = task_key,
active = ctx.task_key,
"take_submission for a non-active task; ignoring"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
let resp = http
.get(OPENROUTER_MODELS_URL)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
fs::write(
&aggregate_path,
serde_json::to_string_pretty(&aggregate.to_json()).unwrap_or_default() + "\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let process = std::env::var(&key_env).ok();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let _ = std::fs::write(
ctx.root_run_dir.join(&subdir).join("run.json"),
serde_json::to_string_pretty(&metadata).unwrap_or_default() + "\n",
);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let _ = std::fs::write(
ctx.root_run_dir.join(&subdir).join("trajectory.jsonl"),
serde_json::to_string(&serde_json::json!({
"sequence": 1,
"timestamp": stamp,
"kind": "infra_error",
"error": format!("infra: {error}"),
}))
.unwrap_or_default()
+ "\n",
);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
data: std::fs::read(task.inputs_dir().join(&f.src)).unwrap_or_default(),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Err(e) = fs::write(&tmp, data).await {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Err(e) = fs::write(&path, data).await {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(
run_dir.join("config.json"),
serde_json::to_string_pretty(&config).unwrap_or_default() + "\n",
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(path, report).await?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
serde_json::from_slice(&std::fs::read(artifacts.path.join("run.json")).unwrap()).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
serde_json::from_slice(&std::fs::read(artifacts.path.join("run.json")).unwrap()).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
serde_json::from_slice(&std::fs::read(artifacts.path.join("run.json")).unwrap()).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
serde_json::from_slice(&std::fs::read(tmp.path().join("config.json")).unwrap()).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let meta: serde_json::Value = serde_json::from_slice(&std::fs::read(run_json).unwrap()).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(&result_path, report_bytes).await?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(&output_path, bytes).await?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(&state_path, bytes).await?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs::write(workdir.join(SUPPORT_NAME), VERIFIER_SUPPORT).await?;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let mut full_env = std::env::vars()
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (rust): platform/archestra-rs/sandbox-core
rust first-partyexpand_more 20 low-confidence finding(s)
tracing::debug!(error = %err, "dagger session child kill errored; reaping");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
let cli = match env::var(DAGGER_CLI_BIN_ENV) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tracing::warn!(error = %err, "dagger session keepalive ping failed");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::info!(target = ?target, "spawning dagger session");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
let image = env::var("ARCHESTRA_DAGGER_RUNTIME_IMAGE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let prebuilt = base_prebuilt_from_env(env::var("ARCHESTRA_CODE_RUNTIME_BASE_PREBUILT").ok());
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tracing::info!(%image, prebuilt, "building warm base image");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
.inspect(|_| tracing::info!("warm base image ready"))
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
.inspect_err(|err| tracing::warn!(error = %err, "warm base image build failed"))
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
let mut file = std::fs::File::create(&path).unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let Ok(stat) = std::fs::read_to_string(format!("/proc/{pid}/stat")) else {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tracing::info!(attempt, "sandbox request recovered on a fresh session");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::warn!(
attempt,
max_attempts,
reason = reason.as_str(),
operation = operation_label(operation),
error_code = err.code(),
error = %err,
"sandbox request failed; retries exhausted"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::warn!(
attempt,
max_attempts,
reason = reason.as_str(),
operation = operation_label(operation),
error_code = err.code(),
error = %err,
"retrying sandbox request on a fresh session"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::warn!(error_code = err.code(), error = %err, "dropping stale sandbox session");
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::debug!(
max = MAX_CONCURRENT_HANDLERS,
"sandbox handler pool saturated; waiting for a permit"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::warn!(
panic = message,
?fault,
recovered = true,
"recovered an engine fault from a sandbox handler panic"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
tracing::error!(
panic = message,
recovered = false,
"recovered a panic in a sandbox handler"
);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
env::var("ARCHESTRA_OTEL_EXPORTER_OTLP_ENDPOINT")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
env::var(key)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
cryptography
rust dependencyexpand_more 26 low-confidence finding(s)
let file = File::open(filename).expect("Failed to open file");
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Ok(version) = env::var("DEP_OPENSSL_VERSION_NUMBER") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_LIBRESSL_VERSION_NUMBER").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_BORINGSSL").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_AWSLC").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY").is_ok_and(|v| !v.is_empty() && v != "0") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Ok(vars) = env::var("DEP_OPENSSL_CONF") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("CARGO_CFG_TARGET_OS").as_deref() == Ok("macos") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let target = env::var("TARGET").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let openssl_static = env::var("OPENSSL_STATIC")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let out_dir = env::var("OUT_DIR").unwrap();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let python = env::var("PYO3_PYTHON").unwrap_or_else(|_| "python3".to_string());
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let python_includes = if let Ok(lib_dir) = env::var("PYO3_CROSS_LIB_DIR") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
.includes(std::env::var_os("DEP_OPENSSL_INCLUDE"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_LIBRESSL_VERSION_NUMBER").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_BORINGSSL").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_AWSLC").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Ok(version) = env::var("DEP_OPENSSL_VERSION_NUMBER") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Ok(vars) = env::var("DEP_OPENSSL_CONF") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if let Ok(version) = env::var("DEP_OPENSSL_VERSION_NUMBER") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var("DEP_OPENSSL_LIBRESSL_VERSION_NUMBER").is_ok() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let is_boringssl = env::var("DEP_OPENSSL_BORINGSSL").is_ok();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let is_awslc = env::var("DEP_OPENSSL_AWSLC").is_ok();
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env::var_os("CARGO_CFG_UNIX").is_some() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
match env::var("CARGO_CFG_TARGET_OS").as_deref() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
&& !env::var("CRYPTOGRAPHY_OPENSSL_NO_LEGACY").is_ok_and(|v| !v.is_empty() && v != "0");
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
Skipped dependencies
Production
- @archestra/shared prod — registry 404
- @better-auth/oauth-provider prod — dist-only: no readable source
- @better-auth/sso prod — dist-only: no readable source
- better-auth prod — dist-only: no readable source
- next prod — tarball exceeds byte cap
- use-stick-to-bottom prod — dist-only: no readable source
- @archestra/app-runtime-rs prod — registry 404
- @archestra/image-rs prod — registry 404
- @archestra/sandbox-rs prod — registry 404
- @azure/identity prod — dist-only: no readable source
- @chonkiejs/core prod — dist-only: no readable source
- @better-auth/api-key prod — dist-only: no readable source
- @gitbeaker/rest prod — dist-only: no readable source
- @google/genai prod — dist-only: no readable source
- @keyv/postgres prod — dist-only: no readable source
- @kubiks/otel-drizzle prod — dist-only: no readable source
- @linear/sdk prod — dist-only: no readable source
- @kubernetes/client-node prod — dist-only: no readable source
- @microsoft/kiota-authentication-azure prod — dist-only: no readable source
- @slack/socket-mode prod — dist-only: no readable source
- @slack/web-api prod — dist-only: no readable source
- @toon-format/toon prod — dist-only: no readable source
- aws4fetch prod — dist-only: no readable source
- fastify-metrics prod — dist-only: no readable source
- jose prod — dist-only: no readable source
- keyv prod — dist-only: no readable source
- @archestra/napi-loader prod — registry 404
- pandas prod — scan budget exceeded
- github.com/moby/go-archive prod — scan budget exceeded
- github.com/moby/profiles/seccomp prod — scan budget exceeded
- github.com/moby/sys/reexec prod — scan budget exceeded
- github.com/moby/sys/user prod — scan budget exceeded
- github.com/opencontainers/runtime-spec prod — scan budget exceeded
- archestra-bench-core prod — scan budget exceeded
- nitpicker-agent prod — scan budget exceeded
- rig-core prod — scan budget exceeded
- tokio prod — scan budget exceeded
- eyre prod — scan budget exceeded
- serde prod — scan budget exceeded
- serde_json prod — scan budget exceeded
- futures prod — scan budget exceeded
- glob prod — scan budget exceeded
- chrono prod — scan budget exceeded
- tempfile prod — scan budget exceeded
- indicatif prod — scan budget exceeded
- archestra_bench prod — scan budget exceeded
- trajectory-analyzer prod — scan budget exceeded
- bench-dashboard prod — scan budget exceeded
- clap prod — scan budget exceeded
- tracing prod — scan budget exceeded
- tracing-subscriber prod — scan budget exceeded
- toml prod — scan budget exceeded
- thiserror prod — scan budget exceeded
- axum prod — scan budget exceeded
- askama prod — scan budget exceeded
- tower-http prod — scan budget exceeded
- pulldown-cmark prod — scan budget exceeded
- percent-encoding prod — scan budget exceeded
- reqwest prod — scan budget exceeded
- url prod — scan budget exceeded
- jsonschema prod — scan budget exceeded
- rmcp prod — scan budget exceeded
- nix prod — scan budget exceeded
- regex prod — scan budget exceeded
- tokio-postgres prod — scan budget exceeded
- bytes prod — scan budget exceeded
- base64 prod — scan budget exceeded
- sha2 prod — scan budget exceeded
- tokio-util prod — scan budget exceeded
- uuid prod — scan budget exceeded
- tl prod — scan budget exceeded
- app_runtime_core prod — scan budget exceeded
- napi prod — scan budget exceeded
- napi-derive prod — scan budget exceeded
- image prod — scan budget exceeded
- image_core prod — scan budget exceeded
- dagger-sdk prod — scan budget exceeded
- futures-util prod — scan budget exceeded
- opentelemetry prod — scan budget exceeded
- opentelemetry_sdk prod — scan budget exceeded
- opentelemetry-otlp prod — scan budget exceeded
- opentelemetry-appender-tracing prod — scan budget exceeded
- tracing-opentelemetry prod — scan budget exceeded
- sandbox_core prod — scan budget exceeded