Close Open Privacy Scan
App Privacy Score
Medium risk · 268 finding(s)
Based on: 4 first-party package(s) · 7/7 deps analyzed
Dependency score: 87 (Low risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz External domains
2001:db8::1abc123.supabase.coaccounts.google.comandroid.stackexchange.comapi.descope.comapi.github.comapi2.amplitude.comapp.scalekit.comastral.shauth.yourdomain.comauth0.config.urlblock.github.iobrew.shbugs.python.orgcdn.amplitude.comcdnjs.cloudflare.comclient.exampledatatracker.ietf.orgdeveloper.apple.comdiscord.comdiscuss.python.orgdocs.descope.comdocs.microsoft.comdocs.propelauth.comdocs.pydantic.devdocs.python.orgdocs.rsdocs.scalekit.comen.wikipedia.orgerrors.pydantic.devesm.shevil.comexam_ple.comfoo.comfreedesktop.orggithub.comgofastmcp.comgoogle-auth.readthedocs.iograph.microsoft.comhorizon.prefect.iohuggingface.cohypothesis.readthedocs.iojson-schema.orglearn.microsoft.comlogin.acme-corp.comlogin.microsoftonline.commodelcontextprotocol.iomy-server.commypy.readthedocs.ionats.iooauth.netoauth2.googleapis.comoidc.config.urlopenid.netpackaging.python.orgpeps.python.orgprefab.prefect.iopydantic-docs.helpmanual.iopygments.orgpypi.orgpython-devtools.helpmanual.ioraw.githubusercontent.comregistry.npmjs.orgrich.readthedocs.iospecifications.freedesktop.orgsupabase.comtag.unifyintent.comtechnet.microsoft.comvalkey.ioworkos.comwww.example.珠宝www.googleapis.comwww.jsonrpc.orgwww.oreilly.comwww.python.orgwww.textualize.iowww.w3.orgwww.xudongz.comyour-app.authkit.appyour-domain.comyour-env.scalekit.comyour-fastmcp-server.comyour-tenant.auth0.comyour-workos-domain.authkit.appyour.server.url
</> First-Party Code
first-party (python): fastmcp_slim
python first-partyfrom opentelemetry.trace import Status, StatusCode
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.trace import Span, SpanKind, Status, StatusCode
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.trace import SpanKind, Status, StatusCode
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.context import Context
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.trace import Span, SpanKind, Status, StatusCode, get_current_span
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry import context as otel_context
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry import propagate, trace
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.context import Context
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.trace import (
INVALID_SPAN,
NoOpTracer,
Span,
SpanKind,
Status,
StatusCode,
Tracer,
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.trace import get_tracer as otel_get_tracer
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.util import types as otel_types
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 80 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 23 locations
low env_fs — Filesystem access. 33 locations
low env_fs — Environment-variable access. 16 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 8 locations
first-party (python)
python first-partyfrom opentelemetry import trace
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.exporter.otlp.proto.grpc.trace_exporter import OTLPSpanExporter
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.resources import Resource
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.trace import TracerProvider
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.trace.export import BatchSpanProcessor
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry import trace
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.exporter.otlp.proto.grpc.trace_exporter import OTLPSpanExporter
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.resources import Resource
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.trace import TracerProvider
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.trace.export import BatchSpanProcessor
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 78 low-confidence finding(s)
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
low env_fs — Environment-variable access. 53 locations
low env_fs — Filesystem access. 2 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 12 locations
low pii_flow — PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime. 9 locations
first-party (python): fastmcp_remote
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): fastmcp_tasks
python first-partyexpand_more 1 low-confidence finding(s)
_ENV_FILE = os.getenv("FASTMCP_ENV_FILE", ".env")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
rich
python dependency yield from progress.track(
sequence,
total=total,
completed=completed,
description=description,
update_period=update_period,
)
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 22 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
low env_fs — Filesystem access. 18 locations
platformdirs
python dependencyexpand_more 33 low-confidence finding(s)
low env_fs — Environment-variable access. 33 locations
pydantic
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 5 locations
pydantic-settings
python dependencyexpand_more 3 low-confidence finding(s)
return parse_env_vars(os.environ, self.case_sensitive, self.env_ignore_empty, self.env_parse_none_str)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.