Close Open Privacy Scan

bolt Snapshot: commit 7359b1a
science engine v1.22
schedule 2026-07-24T14:19:48.218076+00:00

verified_user Application data leak confirmed

High-confidence data exfiltration identified in application code.

smart_toy MCP server detected: anthropic, chromadb, cohere, google-generativeai +9 more — detected in dependencies, not a safety judgment.
Incomplete scan — only 0/200 dependencies were analyzed. Treat the score as provisional.

App Privacy Score

0 /100
High privacy risk — application leak confirmed

High risk · 772 finding(s)

Dependency score: 100 (Low risk)

bar_chart Score Breakdown

pii_flow −60
telemetry −25
egress −15
env_fs −3

list Scan Summary

2 high 48 medium 722 low
First-party packages: 65
Dependency packages: 0
Ecosystem: python

swap_horiz Confirmed data exfiltration in application code

External domains: accelerated-data-science.readthedocs.ioagent-search.readthedocs.ioai-gateway.helicone.aiai-gateway.vercel.shai.api.nvidia.comai.google.devaibadgr.comaip.baidubce.comairweave.aialg.liapi-anurag.eng.macrometa.ioapi-dev.vectorize.ioapi-staging.vectorize.ioapi.01.aiapi.agentql.comapi.aleph-alpha.comapi.anthropic.comapi.apertis.aiapi.app.predibase.comapi.asi1.aiapi.atlassian.comapi.bing.microsoft.comapi.brightdata.comapi.cerebras.aiapi.cloud.llamaindex.aiapi.cloudflare.comapi.cogniswitch.aiapi.cognitive.microsofttranslator.comapi.cometapi.comapi.contextual.aiapi.deepinfra.comapi.deepseek.comapi.docugami.comapi.elevenlabs.ioapi.endpoints.anyscale.comapi.featherless.aiapi.fireworks.aiapi.getguru.comapi.gitbook.comapi.github.comapi.groq.comapi.heroku.comapi.intercom.ioapi.isaacus.comapi.jina.aiapi.keywordsai.coapi.konko.aiapi.linear.appapi.llama.comapi.llmapi.comapi.llmrails.comapi.mangadex.orgapi.minimax.ioapi.mistral.aiapi.monday.comapi.netmind.aiapi.notion.comapi.novita.aiapi.olostep.comapi.openai.comapi.openalex.orgapi.parallel.aiapi.perplexity.aiapi.pipeshift.comapi.playgrounds.networkapi.polygon.ioapi.replicate.comapi.runllm.comapi.sambanova.aiapi.sarvam.aiapi.search.brave.comapi.serpex.devapi.siliconflow.cnapi.stackexchange.comapi.stackoverflowteams.comapi.stepfun.comapi.studio.nebius.aiapi.together.xyzapi.trytldw.aiapi.typecast.aiapi.upstage.aiapi.vectara.ioapi.vectorize.ioapi.x.aiapi.you.comapi.zenrows.comapihub.document360.ioapp.asana.comapp.getguru.comapp.hyperbrowser.aiapp.premai.ioapp.zenrows.comarxiv.orgastra.datastax.comatlassian-python-api.readthedocs.iobeta.api.smabbler.combrowserbase.comcdn.jsdelivr.netcdnapi-ev.kaltura.comchat-api.you.comchat.maritaca.aiclarifai.comcloud.baidu.comcloud.google.comcloud.llamaindex.aicloud.sambanova.aicognitiveservices.azure.comconfluence.atlassian.comconsole.llmrails.comdashboard.psychic.devdashscope.aliyuncs.comdashscope.oss-cn-beijing.aliyuncs.comdata.rcsb.orgdata.sec.govdemo.usememos.comdev.agentql.comdevcenter.heroku.comdeveloper.atlassian.comdeveloper.twitter.comdevelopers.cloudflare.comdevelopers.generativeai.googledevelopers.google.comdevelopers.llamaindex.aidevelopers.oxylabs.iodiscord.comdiscountingcashflows.comdocs.agentql.comdocs.aws.amazon.comdocs.claude.comdocs.firecrawl.devdocs.github.comdocs.helicone.aidocs.hyperbrowser.aidocs.igpt.aidocs.ioniccommerce.comdocs.litellm.aidocs.llamaindex.aidocs.modelslab.comdocs.mongodb.comdocs.neutrinoapp.comdocs.oracle.comdocs.perplexity.aidocs.predibase.comdocs.public.oneportal.content.oci.oraclecloud.comdocs.pydantic.devdocs.python-arango.comdocs.python.orgdocs.ray.iodocs.sambanova.aidocs.steamship.comdocs.sweep.devdocs.tonic.aidocs.vectara.comdocs.voyageai.comdocs.wandb.aidocs.you.comdocs.zyte.comdocumentation.you.comdownload.pytorch.orgdrive.google.comdynamicsessions.ioecc7deb6-26e0-419b-a7f2-0deb934af29a.monsterapi.aiefts.sec.goven.wikipedia.orgeutils.ncbi.nlm.nih.goveverlyai.xyzfastapi.mymagic.aifinance.yahoo.comfinnhub.iogateway.ai.cloudflare.comgenerativelanguage.googleapis.comgithub.comgitlab.comgo.boarddocs.comgoogleapis.devgpt-index.readthedocs.iograph.microsoft.comguides.mangoapps.comhelp.aliyun.comhelp.cleanlab.aihook.us1.make.comhostname.comhuggingface.coicanhazdadjoke.cominference.baseten.coinference.generativeai.us-chicago-1.oci.oraclecloud.comintegrate.api.nvidia.comjoplinapp.orglearn.microsoft.comllama.meta.comllm.api.cloud.yandex.netllm.monsterapi.ailocalai.iologin.microsoftonline.commintlify.s3.us-west-1.amazonaws.commodelslab.commy.telegram.orgmyapp.comneuml.github.ionewspaper.readthedocs.ionla.zapier.comnovita.aioai.endpoints.kepler.ai.cloud.ovh.netoctoai.cloudollama.comopen.bigmodel.cnopen.feishu.cnopen.larksuite.comopenrouter.aiopenweathermap.orgossrdbms-aad.database.windows.netovh.compandas.pydata.orgplaces.googleapis.complatform.claude.complatform.dappier.complatform.neutrinoapp.complatform.openai.complatform.parallel.aiplatform.quip.complatform.stepfun.complg.uwaterloo.capypi.nvidia.compypi.orgqdrant.github.iorayyan.aireadwise.iorealtime.oxylabs.iorealtime.oxyserps-dev.funrich.readthedocs.iorouter.neutrinoapp.comrsshub.apps.jina.ais3.amazonaws.comsandbox.oxylabs.iosarvam.aisc.lfeeder.comscrapfly.iosearch.patentsview.orgseekingalpha.comserpex.devsiliconflow.cnsmabbler.gitbook.iospider.cloudstackoverflow.comstatic.reuters.comsteamship.comstripe.comsupport.intercom.comtaginfo.openstreetmap.orgtinyurl.comunpkg.comus-south.ml.cloud.ibm.comus.helicone.aivercel.comwidget.runllm.comwww.algolia.comwww.alphavantage.cowww.bbc.comwww.bing.comwww.ebi.ac.ukwww.elastic.cowww.engadget.comwww.google.comwww.googleapis.comwww.helicone.aiwww.imdb.comwww.konko.aiwww.llamaindex.aiwww.ncbi.nlm.nih.govwww.pennystockflow.comwww.reuters.comwww.sec.govwww.seltz.aiwww.sitemaps.orgwww.w3.orgwww.wolframalpha.comwww.zyte.comx.comyandex.comydc-index.ioyour-endpointyour-webhook.comyour-work-spaceyour_resource_name.openai.azure.comyoursite.atlassian.com

high first-party (python) User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:40 repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:43
high first-party (python) User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:60 repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:63
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:114 repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:124
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:24 repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:89
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:24 repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:100
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:129
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:139
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:143
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:156
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:168
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:169
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:110 repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:112
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:105 repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:113
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1038 repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1072
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1038 repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1079
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:131 repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:141
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74 repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:24 repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:30
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:58 repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:66
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:58 repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:76
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-mondaydotcom/llama_index/readers/mondaydotcom/base.py:40 repo/llama-index-integrations/readers/llama-index-readers-mondaydotcom/llama_index/readers/mondaydotcom/base.py:57
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:169 repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:172
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:185 repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:189
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:59 repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:67
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:95 repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:107
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:135 repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:145
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:130 repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:132
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:41 repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:41
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:27 repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:27
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:37 repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:41
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:132 repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:131
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:26
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:28
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:35
medium first-party (python) PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:37
medium first-party (python) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:80 repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:81
medium first-party (python): llama-index-integrations/llms/llama-index-llms-mymagic A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:190 repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:196
medium first-party (python): llama-index-integrations/llms/llama-index-llms-maritalk A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:202 repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:204
medium first-party (python): llama-index-integrations/llms/llama-index-llms-maritalk A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:289 repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:293

</> First-Party Code

first-party (python)

python first-party
high pii_flow production #6544517818bdd42b User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:43 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:40 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:43
            response = requests.get(full_url, timeout=10)

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #42bf246e73346c8a User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:63 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:60 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:63
            response = requests.get(full_url, timeout=10)

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium telemetry production #40a235d2a4527ff7 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-aim/llama_index/callbacks/aim/base.py:121
            self._run.track(
                Text(llm_input),
                name="prompt",
                step=self._llm_response_step,
                context={"event_id": event_id},
            )

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6d8deb82d873a025 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-aim/llama_index/callbacks/aim/base.py:128
            self._run.track(
                Text(llm_output),
                name="response",
                step=self._llm_response_step,
                context={"event_id": event_id},
            )

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a2f27460735e398b Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-aim/llama_index/callbacks/aim/base.py:138
                self._run.track(
                    Text(chunk),
                    name="chunk",
                    step=self._llm_response_step,
                    context={"chunk_id": chunk_id, "event_id": event_id},
                )

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #8894005050f39f90 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-arize-phoenix/llama_index/callbacks/arize_phoenix/base.py:10
        from opentelemetry.exporter.otlp.proto.http.trace_exporter import (
            OTLPSpanExporter,

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6242ef5b9add850b Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-arize-phoenix/llama_index/callbacks/arize_phoenix/base.py:13
        from opentelemetry.sdk import trace as trace_sdk

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #8fffee10ddcae4f3 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/callbacks/llama-index-callbacks-arize-phoenix/llama_index/callbacks/arize_phoenix/base.py:14
        from opentelemetry.sdk.trace.export import SimpleSpanProcessor

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow production #da16fe32a220d868 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:124 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:114 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:124
                        DEFAULT_YANDEXGPT_API_BASE, json=payload, headers=header

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #01b3a94da3cad3b6 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:89 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:24 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:89
            print(f"   Answer: {results[0] if isinstance(results, list) else results}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #d71fe99c367af51f PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:100 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:24 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:100
        print(f"   ✅ Graph visualization saved to: {viz_path}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #e5ee6dd47f746fe7 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:129 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:129
            headers=headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #430cc54bd5612880 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:139 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:139
            print(f"Starting creating index {name}, pipeline_id: {pipeline_id}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #f2ba009f2ef949e7 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:143 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:143
            headers=headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #610749c407cb29e8 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:156 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:156
            print(f"Starting ingestion for index {name}, ingestion_id: {ingestion_id}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #059e6bf3872f46af PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:168 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:168
            print(f"ingestion_status {ingestion_status}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #63dcbea913dd994f PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:169 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:169
            print(f"failed_docs: {failed_docs}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #a4dc3b7fe591f2d4 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:112 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:110 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:112
    print(reader.load_data(document_ids=[os.environ.get("FEISHU_DOC_ID")]))

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #9de4cd2abf676dad PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:113 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:105 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:113
    print(reader.load_data(space_id, show_progress=True))

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #065de763bbddbb27 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1072 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1038 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1072
            print(document.extra_info)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #33ccb48ce931e6f0 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1079 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1038 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1079
            print(document.extra_info)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #2151523bb1c649cc A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:141 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:131 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:141
        response = requests.post(SEARCH_TEXT_BASE_URL, headers=headers, data=payload)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #4aa2ed297b65d149 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74
        res = requests.get(url, auth=HTTPBasicAuth(self.username, self.api_key))

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #359d305087b0557e A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:30 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:24 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:30
        response = requests.post(graphql_endpoint, json=payload, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #7ec7732dd38e9856 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:66 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:58 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:66
        response = requests.post(url, headers=headers, data=json.dumps(data))

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #df5009d098dfcd17 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:76 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:58 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:76
                response = requests.put(next_url, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #8998abe1bb128cfa A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-mondaydotcom/llama_index/readers/mondaydotcom/base.py:57 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-mondaydotcom/llama_index/readers/mondaydotcom/base.py:40 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-mondaydotcom/llama_index/readers/mondaydotcom/base.py:57
        response = requests.post(url=self.api_url, json=data, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #8ba8c08538c1bab3 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:172 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:169 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:172
                LAYOUT_ANALYSIS_URL, headers=headers, files=files, data=options

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #0cccb1708bd1201e A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:189 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:185 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:189
                headers=headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #eb17d7f891c26c47 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:67 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:59 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:67
                headers=headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #08493a65a2debb9a A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:107 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:95 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:107
        response = requests.post(api_url, headers=headers, json=data)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #67c89e02d25266c0 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:145 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:135 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:145
        response = requests.post(api_url, headers=headers, json=data)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #17897fec03a18ca0 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:132 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:130 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:132
        response = requests.get(url, auth=auth)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #10bf1b9568c7dc7b A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:41 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:41 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:41
            headers={"Ocp-Apim-Subscription-Key": self.api_key},

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #c75e232d4c839204 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:27 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:27 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:27
            headers={"Ocp-Apim-Subscription-Key": self.api_key},

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #6a4b117ac70963e8 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:41 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:37 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:41
        response = requests.get(url, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #9b31444105046fdf A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:131 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:132 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:131
                headers={
                    "Authorization": f"Bearer {self.api_key}",
                },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #9e43927a2375f1a7 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:26 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:26
        print(f"✅ Search returned {len(results)} results (as Document objects):")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #cca5a68842809dfb PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:28 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:28
            print(f"\nResult {i}:")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #fa64c02907fcc660 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:35 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:35
        print(f"✅ Tool list has {len(tool_list)} tools:")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #6c5f894ee99c1202 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:37 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:37
            print(f"   - {t.metadata.name}: {t.metadata.description[:60]}...")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow production #c42cf970eb7396ae A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:81 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:80 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:81
        response = requests.get(url, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 508 low-confidence finding(s)
low env_fs test-only Excluded from app score #c0fbd084608f0cdb Filesystem access.
repo/docs/examples/discover_llamaindex/document_management/group_conversations.py:30
with open(data_file, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #e89390ff752f595e Filesystem access.
repo/docs/examples/discover_llamaindex/document_management/group_conversations.py:77
with open("conversation_docs.json", "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #05e4bbac343eec2b Filesystem access.
repo/docs/scripts/prepare_for_build.py:119
    with open(MKDOCS_YML) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #b155dcbba0967612 Filesystem access.
repo/docs/scripts/prepare_for_build.py:144
                    with open(toml_path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #eb8e5a24e9012725 Filesystem access.
repo/docs/scripts/prepare_for_build.py:176
                    with open(os.path.join(full_path, module_name), "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #548a81667f8133ec Filesystem access.
repo/docs/scripts/prepare_for_build.py:194
    with open(MKDOCS_YML, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #12d4a9597e1bfffb Filesystem access.
repo/docs/scripts/prepare_for_build.py:202
    with open("./src/content/docs/framework/CHANGELOG.md", "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #a854ca1c5bd59c57 Filesystem access.
repo/docs/scripts/prepare_for_build.py:210
    with open("./src/content/docs/framework/CHANGELOG.md", "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #53385048cddca26d Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-adapter/llama_index/embeddings/adapter/utils.py:39
        with open(
            os.path.join(output_path, "config.json"), "w", encoding="utf-8"
        ) as fOut:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #cb749da7ede9985a Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-adapter/llama_index/embeddings/adapter/utils.py:48
        with open(os.path.join(input_path, "config.json"), encoding="utf-8") as fIn:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #64e5b688af75f35e Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-bedrock/llama_index/embeddings/bedrock/base.py:259
        aws_region = aws_region or os.getenv("AWS_REGION")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ffd1e148f7635877 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-bedrock/llama_index/embeddings/bedrock/base.py:260
        aws_access_key_id = aws_access_key_id or os.getenv("AWS_ACCESS_KEY_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c3d70742e682340e Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-bedrock/llama_index/embeddings/bedrock/base.py:261
        aws_secret_access_key = aws_secret_access_key or os.getenv(
            "AWS_SECRET_ACCESS_KEY"
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a3ef94c329095c65 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-bedrock/llama_index/embeddings/bedrock/base.py:264
        aws_session_token = aws_session_token or os.getenv("AWS_SESSION_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1b8f6dea57d38dc4 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-clarifai/llama_index/embeddings/clarifai/base.py:52
        if pat is None and os.environ.get("CLARIFAI_PAT") is not None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3592e1595ef87823 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-clarifai/llama_index/embeddings/clarifai/base.py:53
            pat = os.environ.get("CLARIFAI_PAT")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dc6b615c4ee3b3c9 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-clarifai/llama_index/embeddings/clarifai/base.py:55
        if not pat and os.environ.get("CLARIFAI_PAT") is None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #1a1128e269d7fb0f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-cloudflare-workersai/llama_index/embeddings/cloudflare_workersai/base.py:90
        response = self._session.post(
            API_URL_TEMPLATE.format(self.account_id, self.model), json={"text": texts}
        ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #5713310ad1b86e8d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-cloudflare-workersai/llama_index/embeddings/cloudflare_workersai/base.py:109
            async with session.post(
                API_URL_TEMPLATE.format(self.account_id, self.model),
                json={"text": texts},
                headers=headers,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #cb5a5b14123f0681 Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-cohere/llama_index/embeddings/cohere/base.py:298
            with open(image_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c0f65ac63b19a1ff Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-deepinfra/llama_index/embeddings/deepinfra/base.py:75
        self._api_token = api_token or os.getenv(ENV_VARIABLE, None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #05938e2d462cb24e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-deepinfra/llama_index/embeddings/deepinfra/base.py:95
            response = requests.post(
                url,
                json={
                    "inputs": chunk,
                },
                headers=self._get_headers(),
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #fb3aec778ba4ee28 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-deepinfra/llama_index/embeddings/deepinfra/base.py:128
                async with session.post(
                    url,
                    json={
                        "inputs": chunk,
                    },
                    headers=self._get_headers(),
                ) as resp:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #cf511efed963f6ae Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:34
NEO4J_USERNAME = os.getenv("NEO4J_USERNAME")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #9de3cad823b9cfd3 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:35
NEO4J_PASSWORD = os.getenv("NEO4J_PASSWORD")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #26903f349a2ca31a Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:36
NEO4J_URL = os.getenv("NEO4J_URL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #3171c64113f0fcfd Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:37
NEO4J_DATABASE = os.getenv("NEO4J_DATABASE")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #f892c5e221b5a921 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:327
    args.quant_config = os.getenv("QUANT_CONFIG", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #6fc85d427b5bcf9c PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:426 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:35 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/embeddings/llama-index-embeddings-gaudi/examples/graphrag.py:426
    print(response.response.split("<|assistant|>")[-1].strip())

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs production #0f128def73f8a8d4 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-google-genai/llama_index/embeddings/google_genai/base.py:200
        api_key = api_key or os.getenv("GOOGLE_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #6fa3bb2b0b962d53 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-google-genai/llama_index/embeddings/google_genai/base.py:201
        vertexai = vertexai_config is not None or os.getenv(
            "GOOGLE_GENAI_USE_VERTEXAI", False
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3953b19bb647e1f9 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-google-genai/llama_index/embeddings/google_genai/base.py:204
        project = (vertexai_config or {}).get("project") or os.getenv(
            "GOOGLE_CLOUD_PROJECT", None
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d9b1434c76da69a5 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-google-genai/llama_index/embeddings/google_genai/base.py:207
        location = (vertexai_config or {}).get("location") or os.getenv(
            "GOOGLE_CLOUD_LOCATION", None
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e87a1a1007df8ab0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-heroku/llama_index/embeddings/heroku/base.py:163
            response = self._client.post(
                f"{self.base_url}/v1/embeddings",
                json={
                    "input": text,
                    "model": self.model,
                },
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #05a9b1fe75b0216f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-heroku/llama_index/embeddings/heroku/base.py:187
            response = await self._aclient.post(
                f"{self.base_url}/v1/embeddings",
                json={
                    "input": text,
                    "model": self.model,
                },
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #cddfc8d1e0dd25a5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-huggingface/llama_index/embeddings/huggingface/utils.py:85
        response = requests.get(pooling_config_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #d779a26520f0cd20 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:40
        if not (apikey or "WATSONX_APIKEY" in os.environ) and not (

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #967f5924af66272b Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:41
            token or "WATSONX_TOKEN" in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #df183ccf402be890 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:51
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0188ee43dcd47f59 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:62
            and "WATSONX_TOKEN" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #bed75e83c1f3f6a4 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:64
            and "WATSONX_PASSWORD" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #6db58f219b92ac76 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:66
            and "WATSONX_APIKEY" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #713dbb11d5648ca8 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:76
        elif token or "WATSONX_TOKEN" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5565df556ff85483 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:81
        elif password or "WATSONX_PASSWORD" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fbe5241d49d351f8 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-ibm/llama_index/embeddings/ibm/utils.py:90
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #317665422da7b9b0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-jinaai/llama_index/embeddings/jinaai/base.py:62
        resp = self._session.post(  # type: ignore
            self.api_url,
            json=input_json,
        ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #082ef15fd1f807a5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-jinaai/llama_index/embeddings/jinaai/base.py:117
            async with session.post(
                self.api_url,
                json=input_json,
                headers=headers,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #153e47f26b75dcdd Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-jinaai/llama_index/embeddings/jinaai/base.py:155
    with open(file_path, "rb") as image_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #318bef5f5f935fbb Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-llm-rails/llama_index/embeddings/llm_rails/base.py:60
            response = self.session.post(
                "https://api.llmrails.com/v1/embeddings",
                json={"input": [text], "model": self.model_id},
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a4d3766944176cff Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-llm-rails/llama_index/embeddings/llm_rails/base.py:93
                response = await client.post(
                    "https://api.llmrails.com/v1/embeddings",
                    headers={"X-API-KEY": self.api_key},
                    json={"input": [text], "model": self.model_id},
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #7519857161da06a1 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-mixedbreadai/llama_index/embeddings/mixedbreadai/base.py:84
            api_key = api_key or os.environ["MXBAI_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #cb22c1286d5fe248 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-netmind/llama_index/embeddings/netmind/base.py:35
        api_key = api_key or os.environ.get("NETMIND_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #9004308e83d21988 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-nvidia/llama_index/embeddings/nvidia/base.py:31
        default_factory=lambda: os.getenv("NVIDIA_BASE_URL", BASE_URL),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #5a3bea4a9e062f79 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-oci-data-science/llama_index/embeddings/oci_data_science/client.py:410
            response = self._client.post(
                self.endpoint,
                headers=self._prepare_headers(headers=headers),
                auth=self.auth,
                json=payload,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #96c0a10cd4d7f1ce Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-oci-data-science/llama_index/embeddings/oci_data_science/client.py:547
            response = await self._client.post(
                self.endpoint,
                headers=self._prepare_headers(headers=headers),
                auth=self.auth,
                json=payload,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #cf11f394f87d2f09 Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-oci-genai/llama_index/embeddings/oci_genai/base.py:190
                        with open(
                            oci_config.get("security_token_file"), encoding="utf-8"
                        ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #bc0a7306f201be18 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-openai/llama_index/embeddings/openai/utils.py:154
    openai_api_key = api_key or os.environ.get("OPENAI_API_KEY", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #4107119187fbbea2 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-siliconflow/llama_index/embeddings/siliconflow/base.py:209
            response = session.post(
                self.base_url, json=input_json, headers=self._headers
            ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #41a33c4b1b6927e5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-siliconflow/llama_index/embeddings/siliconflow/base.py:228
            async with session.post(
                self.base_url, json=input_json, headers=self._headers
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #178c6e3ccf5e1ca2 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-text-embeddings-inference/llama_index/embeddings/text_embeddings_inference/base.py:88
            response = client.post(
                f"{self.base_url}{self.endpoint}",
                headers=headers,
                json=json_data,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #cf25eb5117a48ac1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-text-embeddings-inference/llama_index/embeddings/text_embeddings_inference/base.py:110
            response = await client.post(
                f"{self.base_url}{self.endpoint}",
                headers=headers,
                json=json_data,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #4ea6d37d46eff9e8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-textembed/llama_index/embeddings/textembed/base.py:90
        with requests.post(
            f"{self.base_url}/embedding",
            headers=headers,
            json=json_data,
            timeout=self.timeout,
        ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #07091702f5208c21 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-textembed/llama_index/embeddings/textembed/base.py:123
            async with session.post(
                f"{self.base_url}/embedding",
                headers=headers,
                json=json_data,
                timeout=self.timeout,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #970576fc7d39b180 Environment-variable access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-together/llama_index/embeddings/together/base.py:29
        api_key = api_key or os.environ.get("TOGETHER_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #1d975a8b6d3837d8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-together/llama_index/embeddings/together/base.py:57
            response = session.post(
                self.api_base.strip("/") + "/embeddings",
                headers=headers,
                json={"input": text, "model": model_api_string},
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #9c73d52a8cd0381f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-together/llama_index/embeddings/together/base.py:100
                response = await client.post(
                    self.api_base.strip("/") + "/embeddings",
                    headers=headers,
                    json={"input": text, "model": model_api_string},
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f55343aecf260909 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:123
                    response = requests.post(
                        DEFAULT_YANDEXGPT_API_BASE, json=payload, headers=header
                    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2fa87a7eb102bb63 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/base.py:163
                        async with session.post(
                            DEFAULT_YANDEXGPT_API_BASE, json=payload, headers=header
                        ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #9cee588f4131d160 Filesystem access.
repo/llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt/llama_index/embeddings/yandexgpt/util.py:60
        with open(fn, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dcdc43bdd29f078c Environment-variable access.
repo/llama-index-integrations/graph_rag/llama-index-graph-rag-cognee/example.py:24
    api_key = os.getenv("OPENAI_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #440562d87ce85995 Filesystem access.
repo/llama-index-integrations/indices/llama-index-indices-managed-bge-m3/llama_index/indices/managed/bge_m3/base.py:133
        with open(Path(persist_dir) / "multi_embed_store.pkl", "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #999db8d191c6ca8a Filesystem access.
repo/llama-index-integrations/indices/llama-index-indices-managed-bge-m3/llama_index/indices/managed/bge_m3/base.py:158
            open(Path(persist_dir) / "multi_embed_store.pkl", "rb")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fde7bc09155f9223 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:78
        self.workspace_id = workspace_id or os.environ.get("DASHSCOPE_WORKSPACE_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d53535e5796ed481 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:79
        self._api_key = api_key or os.environ.get("DASHSCOPE_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c5d557a763fe711c Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:80
        self._base_url = os.environ.get("DASHSCOPE_BASE_URL", None) or base_url

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #93150777328ca7c0 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:111
        workspace_id = workspace_id or os.environ.get("DASHSCOPE_WORKSPACE_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4da07be0923db9d5 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:112
        api_key = api_key or os.environ.get("DASHSCOPE_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #66b675bed5e72b42 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:115
            or os.environ.get("DASHSCOPE_BASE_URL", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e57419b9e80b8108 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:126
        response = requests.put(
            base_url + UPSERT_PIPELINE_ENDPOINT,
            data=json.dumps(pipeline_create),
            headers=headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #9cc238d54ab65058 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:141
        response = requests.post(
            base_url + START_PIPELINE_ENDPOINT.format(pipeline_id=pipeline_id),
            headers=headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #7d1e72999f085e0c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:224
        response = requests.put(
            self._base_url + INSERT_DOC_ENDPOINT.format(pipeline_id=pipeline_id),
            data=json.dumps(doc_insert),
            headers=self._headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #fe49d22ae6026405 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/base.py:267
        response = requests.post(
            self._base_url + DELETE_DOC_ENDPOINT.format(pipeline_id=pipeline_id),
            json=doc_delete,
            headers=self._headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #4e41c8f36b0d178c Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/retriever.py:47
        self.workspace_id = workspace_id or os.environ.get("DASHSCOPE_WORKSPACE_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #adc178a1120bcfbc Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/retriever.py:48
        self._api_key = api_key or os.environ.get("DASHSCOPE_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dd088685538a53d8 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/retriever.py:67
            os.environ.get("DASHSCOPE_BASE_URL", None) or DASHSCOPE_DEFAULT_BASE_URL

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #c56f1d2938b86370 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/utils.py:6
    response = requests.post(base_url, headers=headers, json=params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f606632f9c11d276 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/utils.py:16
    response = requests.get(base_url, headers=headers, params=params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #274d8622fd2042db Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-dashscope/llama_index/indices/managed/dashscope/utils.py:36
        response = requests.get(
            request_url,
            headers=headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #109a865fec8f69ab Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/base.py:402
                    image_bytes = httpx.get(document.image_url).content

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #760ccae4d2deb63b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/base.py:561
                    image_bytes = httpx.get(document.image_url).content

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #885f738fd35b958f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/base.py:631
                    image_bytes = httpx.get(document.image_url).content

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #68ecdebe31edb66e Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/utils.py:25
            self.api_key = os.getenv("LANCEDB_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #dc3054fa9ab53f9f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/utils.py:288
        image_bytes = httpx.get(query).content

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #d4c7d07fc5a877f0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-lancedb/llama_index/indices/managed/lancedb/utils.py:362
        image_bytes = httpx.get(query).content

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #bc2d391fd7131d72 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-vectara/llama_index/indices/managed/vectara/base.py:88
            os.environ.get("VECTARA_CORPUS_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d13f80319807e439 Environment-variable access.
repo/llama-index-integrations/indices/llama-index-indices-managed-vectara/llama_index/indices/managed/vectara/base.py:91
        self._vectara_api_key = vectara_api_key or os.environ.get("VECTARA_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4b069656f3977a36 Filesystem access.
repo/llama-index-integrations/indices/llama-index-indices-managed-vectara/llama_index/indices/managed/vectara/base.py:362
        files = {"file": (filename, open(file_path, "rb"))}

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #df6d4482ad054a2a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/indices/llama-index-indices-managed-vectara/llama_index/indices/managed/vectara/base.py:385
        response = self._session.post(
            f"{self._base_url}/v2/corpora/{valid_corpus_key}/upload_file",
            files=files,
            verify=True,
            headers=headers,
            timeout=self.vectara_api_timeout,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #10cb5e744e7600eb Environment-variable access.
repo/llama-index-integrations/node_parser/llama-index-node-parser-relational-dashscope/llama_index/node_parser/dashscope/base.py:77
        DASHSCOPE_API_KEY = os.environ.get("DASHSCOPE_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #87dce7a335c54d33 Environment-variable access.
repo/llama-index-integrations/node_parser/llama-index-node-parser-relational-dashscope/llama_index/node_parser/dashscope/base.py:87
            os.getenv("DASHSCOPE_BASE_URL", "https://dashscope.aliyuncs.com")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #4a9706629bc7ba33 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/node_parser/llama-index-node-parser-relational-dashscope/llama_index/node_parser/dashscope/base.py:91
            response = requests.post(
                service_url, data=json.dumps(my_input), headers=headers
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #d0a7de7eb91cb0d5 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-google-rerank/llama_index/postprocessor/google_rerank/base.py:79
            self.project_id = os.environ.get("GOOGLE_CLOUD_PROJECT")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1eab2b58f42dca7c Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-pinecone-native-rerank/llama_index/postprocessor/pinecone_native_rerank/base.py:38
            api_key = api_key or os.environ["PINECONE_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e99558727ef9a0af Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-alibabacloud-aisearch/llama_index/readers/alibabacloud_aisearch/base.py:127
                content=base64.b64encode(open(file_path, "rb").read()).decode(),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #20637a842418972c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-alibabacloud-aisearch/llama_index/readers/alibabacloud_aisearch/base.py:265
                content=base64.b64encode(open(file_path, "rb").read()).decode(),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1127f7070513750f Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-azstorage-blob/llama_index/readers/azstorage_blob/base.py:145
            with open(file=download_file_path, mode="wb") as download_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8e0b28e3ebd142d9 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-azstorage-blob/llama_index/readers/azstorage_blob/base.py:245
                with open(file=download_file_path, mode="wb") as download_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #4b6ad24b8fe25b4a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-bilibili/llama_index/readers/bilibili/base.py:33
            result = requests.get(sub_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #ede638c2c51792d0 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:29
        if os.getenv("BITBUCKET_USERNAME") is None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8a99b173b05a59b2 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:31
        if os.getenv("BITBUCKET_API_KEY") is None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1e06cf74bc8045d8 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:44
        username = os.getenv("BITBUCKET_USERNAME")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d72e5d911923a335 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:45
        api_token = os.getenv("BITBUCKET_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #c26fcb93bd7378c4 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:60
            response = requests.get(repos_url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2bc94de362725078 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:82
        response = requests.get(content_url, headers=headers, params=query_params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #dc4a5863a7dc1d21 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-bitbucket/llama_index/readers/bitbucket/base.py:114
        response = requests.get(content_url, headers=headers, params=query_params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #093f200fffbd2f8d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-boarddocs/llama_index/readers/boarddocs/base.py:65
        response = requests.post(meeting_list_url, headers=self.headers, data=data)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e1667d93c856262b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-boarddocs/llama_index/readers/boarddocs/base.py:89
        response = requests.post(agenda_url, headers=self.headers, data=data)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #fb93e38cb3177200 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-box/examples/box_reader.py:19
    client_id = os.getenv("BOX_CLIENT_ID", "YOUR_BOX_CLIENT_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #e62f69f72dd60538 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-box/examples/box_reader.py:20
    client_secret = os.getenv("BOX_CLIENT_SECRET", "YOUR_BOX_CLIENT_SECRET")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #c96ef8ce8a2f302c Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-box/examples/box_reader.py:23
    enterprise_id = os.getenv("BOX_ENTERPRISE_ID", "YOUR_BOX_ENTERPRISE_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #ce00aaa0e79eb5fe Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-box/examples/box_reader.py:24
    ccg_user_id = os.getenv("BOX_USER_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0e8e336495d56a1c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-box/llama_index/readers/box/BoxAPI/box_api.py:161
    with open(file_path, "wb") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e55a04d44c6b0b4e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-box/llama_index/readers/box/BoxAPI/box_api.py:262
    resp = requests.get(url, headers={"Authorization": f"Bearer {access_token}"})

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #276c24501fb87a1f Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-chatgpt-plugin/llama_index/readers/chatgpt_plugin/base.py:24
        self._bearer_token = bearer_token or os.getenv("BEARER_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #f3a3d9f192272607 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-chatgpt-plugin/llama_index/readers/chatgpt_plugin/base.py:41
        res = requests.post(
            f"{self._endpoint_url}/query", headers=headers, json={"queries": queries}
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #af646ca385b87263 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-confluence/llama_index/readers/confluence/base.py:60
        with open(custom_file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5109cfec7bd4b56b Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-confluence/llama_index/readers/confluence/base.py:204
                api_token = os.getenv(CONFLUENCE_API_TOKEN)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #95bacc81d8669cfe Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-confluence/llama_index/readers/confluence/base.py:210
                    user_name = os.getenv(CONFLUENCE_USERNAME)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #36d9902efdc2f6fb Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-confluence/llama_index/readers/confluence/base.py:211
                    password = os.getenv(CONFLUENCE_PASSWORD)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #7327d375a9233e36 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-couchdb/llama_index/readers/couchdb/base.py:54
        db = self.client.get(db_name)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #06963da62b4a7921 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dad-jokes/llama_index/readers/dad_jokes/base.py:19
        response = requests.get(
            "https://icanhazdadjoke.com/", headers={"Accept": "application/json"}
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #f2b8ee0d3c074370 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:31
DASHSCOPE_DEFAULT_DC_CATEGORY = os.getenv(
    "DASHSCOPE_DEFAULT_DC_CATEGORY", default="default"
)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c6460415257f6964 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:102
            api_key = os.getenv("DASHSCOPE_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #58a506cbc0d6674a Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:115
            return os.getenv("DASHSCOPE_WORKSPACE_ID", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #db2c75c7ac7e0565 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:125
            return os.getenv("DASHSCOPE_CATEGORY_ID", DASHSCOPE_DEFAULT_DC_CATEGORY)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #38fe5a28d4bd9346 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:135
                os.getenv("DASHSCOPE_BASE_URL", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e039f0b6b6be6bd2 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:162
        with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #94617f5761434fff Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:169
                response = await client.post(
                    url,
                    headers=headers,
                    json={
                        "lease_id": upload_file_lease_result.lease_id,
                        "parser": ResultType.DASHSCOPE_DOCMIND.value,
                    },
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #5b9d7175b17a395c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:195
                response = client.post(
                    url,
                    headers=headers,
                    json={
                        "file_name": os.path.basename(file_path),
                        "size_bytes": os.path.getsize(file_path),
                        "content_md5": get_file_md5(file_path),
                    },
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8bb6f07d72caab2e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:239
                    response = await client.post(
                        result_url, headers=headers, json={"file_id": data_id}
                    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #643f7eb34390c1d5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/base.py:284
                response = await client.post(
                    status_url, headers=headers, json={"file_id": data_id}
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #c9e4f5a62f3ae1b2 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/domain/lease_domains.py:50
                response = requests.put(self.url, data=file, headers=self.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8ab6cd4646f93d8a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/domain/lease_domains.py:52
                response = requests.post(self.url, data=file, headers=self.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #f79b2361ffd47e8f Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-dashscope/llama_index/readers/dashscope/utils.py:30
    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #26e3bceed16e9669 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-dashvector/llama_index/readers/dashvector/base.py:64
        collection = self._client.get(collection_name)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #763d086b3979942a Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-discord/llama_index/readers/discord/base.py:114
            discord_token = os.environ["DISCORD_TOKEN"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1e62551519fb3d88 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-docstring-walker/llama_index/readers/docstring_walker/base.py:116
        with open(path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fd96d90c970a5132 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:44
    access_token: Optional[str] = os.environ.get("DOCUGAMI_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7a6acbcfce9d855e Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:87
        access_token: Optional[str] = os.environ.get("DOCUGAMI_API_KEY"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #9f9d4cabb5b43dab Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:220
            response = requests.get(
                url,
                headers={"Authorization": f"Bearer {self.access_token}"},
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3195263e5d544bd6 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:241
            response = requests.request(
                "GET",
                url,
                headers={"Authorization": f"Bearer {self.access_token}"},
                data={},
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f4f2c2782556a5b7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:267
            response = requests.request(
                "GET",
                url,
                headers={"Authorization": f"Bearer {self.access_token}"},
                data={},
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #c4cd6b73167e092d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:295
                response = requests.request(
                    "GET",
                    f"{artifact_url}/content",
                    headers={"Authorization": f"Bearer {self.access_token}"},
                    data={},
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e3581c520c3a5cfb Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-docugami/llama_index/readers/docugami/base.py:339
        response = requests.request(
            "GET",
            url,
            headers={"Authorization": f"Bearer {self.access_token}"},
            data={},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #b2ddcdbf9196017b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-document360/llama_index/readers/document360/base.py:74
        response = requests.request(
            method, url, headers=headers, params=params, data=data, json=json
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #235fe82b489849a8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-earnings-call-transcript/llama_index/readers/earnings_call_transcript/utils.py:56
    response = requests.get(
        f"https://discountingcashflows.com/api/transcript/{ticker}/{quarter}/{year}/",
        auth=("user", "pass"),
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #57f5c1efb861bc61 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-elasticsearch/llama_index/readers/elasticsearch/base.py:81
        res = self._client.post(f"{self.index}/_search", json=query).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #49d75d743d32d797 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-feedly-rss/llama_index/readers/feedly_rss/base.py:37
            auth_file.write_text(auth.strip())

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #365ade96e0995fdf Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:91
        response = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0320630fb55039d4 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:99
        response = requests.post(url, data=json.dumps(data), headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #274e64b817bd5c4b Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:109
    app_id = os.environ.get("FEISHU_APP_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e2f0e42ce5448a04 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:110
    app_secret = os.environ.get("FEISHU_APP_SECRET")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #66419746dba871e3 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-feishu-docs/llama_index/readers/feishu_docs/base.py:112
    print(reader.load_data(document_ids=[os.environ.get("FEISHU_DOC_ID")]))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #de45889514582c3b Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-file/llama_index/readers/file/html/base.py:36
        with open(file, encoding="utf-8") as html_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #48af5e35960d79bc Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-file/llama_index/readers/file/paged_csv/base.py:43
        with open(file, encoding=self._encoding) as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f0735206c1eb63bb Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-file/llama_index/readers/file/rtf/base.py:35
        with open(str(input_file)) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #25e9e79294e29158 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-file/llama_index/readers/file/tabular/base.py:49
        with open(file) as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #30cc0ef77fa390be Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:97
            with open(env_path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b892e43e4c55122c Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:102
                        os.environ[key.strip()] = value.strip()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #efb7e567e9fbd81a Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:105
    api_token = os.getenv("GITBOOK_API_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #75aec8b0f3094562 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/base.py:106
    space_id = os.getenv("GITBOOK_SPACE_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0e9393573d9ccd34 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-gitbook/llama_index/readers/gitbook/gitbook_client.py:30
            response = requests.get(url, headers=self.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #b5c134eb89284839 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:24
    with open(key_path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #7c4ab6bf4ddd3d10 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:33
    app_id = os.getenv("GITHUB_APP_ID", "123456")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #8da277a7df5667ba Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:34
    installation_id = os.getenv("GITHUB_INSTALLATION_ID", "789012")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #ca2a719332e237c0 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:37
    private_key_path = os.getenv("GITHUB_PRIVATE_KEY_PATH", "path/to/your-app.private-key.pem")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #20fce8d67ff54de7 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:43
        private_key = os.getenv("GITHUB_PRIVATE_KEY", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #667ec1ba61152e35 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:83
    app_id = os.getenv("GITHUB_APP_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #0a5da7aa3ae62496 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:84
    installation_id = os.getenv("GITHUB_INSTALLATION_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #f97667b2236f6721 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:85
    private_key = os.getenv("GITHUB_PRIVATE_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #0a016e849e919bfd PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:113 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:85 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:113
    print(f"Loaded {len(documents)} Python files")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs test-only Excluded from app score #7f6f341ece235844 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:119
    app_id = os.getenv("GITHUB_APP_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #029a714ccf8234c4 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:120
    installation_id = os.getenv("GITHUB_INSTALLATION_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #318ab0eb101750fa Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:121
    private_key = os.getenv("GITHUB_PRIVATE_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #fc5bed4f579f5cf2 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:136 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:121 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:136
    print(f"Token expires at: {github_app_auth._token_expires_at}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #027356903a1767a1 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:147 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:121 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:147
    print(f"New token fetched, expires at: {github_app_auth._token_expires_at}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs test-only Excluded from app score #cfde93e6c30df949 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/examples/github_app_example.py:165
    example = os.getenv("EXAMPLE", "basic")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c3120aa46790a3e0 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/collaborators/github_client.py:103
                github_token = os.getenv("GITHUB_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #ec13c5d61e0b6981 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/github_app_auth.py:173
                response = await client.post(url, headers=headers, timeout=10.0)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #497e4febfd3b861b Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/issues/github_client.py:104
                github_token = os.getenv("GITHUB_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0c16f39ac09c0e63 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/base.py:1038
    github_client = GithubClient(github_token=os.environ["GITHUB_TOKEN"], verbose=True)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c69c543c40e8e6d9 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-github/llama_index/readers/github/repository/github_client.py:329
                github_token = os.getenv("GITHUB_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ebd61ffa6b751795 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/calendar/base.py:137
            with open("token.json", "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b3ef74ccc213d7a3 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/chat/base.py:281
            with open("token.json", "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #87f80a62555aa422 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/docs/base.py:125
                with open("credentials.json") as json_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #bf9b45dc19520922 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/docs/base.py:133
            with open("token.json", "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #27ff2d044139ed99 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:104
            with open(credentials_path, encoding="utf-8") as json_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #56a6ae0171cfa0d9 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:108
            with open(token_path, encoding="utf-8") as json_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #6904ab1a0d88d747 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:112
            with open(service_account_key_path, encoding="utf-8") as json_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7898043371c7bdbc Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:196
                with open(self.token_path, "w", encoding="utf-8") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #6501e3b76180994a Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:485
            with open(new_file_name, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #05645fc8562c1061 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/drive/base.py:728
            with open(downloaded_file, "rb") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b2fa44b541fdcf4a Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/gmail/base.py:85
            with open("token.json", "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fba0e4f8ba039746 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/keep/base.py:58
            with open("keep_credentials.json") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #9d723e79b9f55a45 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:39
        self.api_key = api_key or os.getenv("GOOGLE_MAPS_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #8a4d85ec44a7de89 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/maps/base.py:141
        response = requests.post(SEARCH_TEXT_BASE_URL, headers=headers, data=payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #5096b839cbb890ba Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-google/llama_index/readers/google/sheets/base.py:205
            with open("token.json", "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #95d9b5ebb202e8f2 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-gpt-repo/llama_index/readers/gpt_repo/base.py:44
    with open(ignore_file_path) as ignore_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #aca654e138f05ef3 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-gpt-repo/llama_index/readers/gpt_repo/base.py:79
                with open(file_path, errors="ignore", encoding=encoding) as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #b504828c90a0ce04 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-guru/llama_index/readers/guru/base.py:75
        response = requests.get(initial_url, auth=self.guru_auth)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #45c4e62b944c0a0e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-guru/llama_index/readers/guru/base.py:88
            response = requests.get(url, auth=self.guru_auth)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #74b7d3c845315188 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-guru/llama_index/readers/guru/base.py:111
        response = requests.get(url, auth=self.guru_auth, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #66f8ad8a555f3de0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-guru/llama_index/readers/guru/base.py:155
        response = requests.get(url, headers=headers, auth=self.guru_auth)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a1c137cd529c1f73 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-hatena-blog/llama_index/readers/hatena_blog/base.py:74
        res = requests.get(url, auth=HTTPBasicAuth(self.username, self.api_key))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #e9903a8490297051 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-huggingface-fs/llama_index/readers/huggingface_fs/base.py:32
        test_data = self.fs.read_bytes(path)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8c85f220d64e7e4a Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-huggingface-fs/llama_index/readers/huggingface_fs/base.py:40
                with open(tmp / "tmp.jsonl.gz", "wb") as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #23722afe87ef8f1a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-intercom/llama_index/readers/intercom/base.py:90
        response = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #933b6e63b68b947e Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-jaguar/llama_index/readers/jaguar/base.py:255
        with open("/tmp/debugjaguarrdr.log", "a") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0cc0e6b03203fd25 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-joplin/llama_index/readers/joplin/base.py:73
        if "JOPLIN_ACCESS_TOKEN" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7f5a42defccfc05a Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-joplin/llama_index/readers/joplin/base.py:74
            return os.environ["JOPLIN_ACCESS_TOKEN"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #2a00dbed31b309e4 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-joplin/llama_index/readers/joplin/base.py:87
            with urllib.request.urlopen(req_note) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8b852b5a27d18ab5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-joplin/llama_index/readers/joplin/base.py:110
        with urllib.request.urlopen(req_folder) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0937e5aac5759847 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-joplin/llama_index/readers/joplin/base.py:116
        with urllib.request.urlopen(req_tag) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #beb589c5486b7b7c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-json/llama_index/readers/json/base.py:100
        with open(input_file, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #902d5391fefc7dd5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-kaltura/llama_index/readers/kaltura_esearch/base.py:177
            return requests.get(cap_json_url).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #5da5ef9fc89178e0 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:69
            os.environ["TIKA_SERVER_ENDPOINT"] = tika_server_url

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ec4e5d2830b32430 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:74
            os.environ["TIKA_SERVER_JAR"] = tika_server_jar_path

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e87a17b620871363 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:80
                os.environ["TIKA_SERVER_JAR"] = str(cached_jar)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3cc03fd1c8146f71 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:83
                os.environ["TIKA_SERVER_JAR"] = str(cached_jar)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #32a3d764bc1396e8 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:90
                os.environ["TIKA_SERVER_ENDPOINT"] = "http://localhost:9998"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #25012fd9b6ae6efb Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-legacy-office/llama_index/readers/legacy_office/reader.py:101
        os.environ["TIKA_SERVER_ENDPOINT"] = "http://localhost:9998"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #ec84ac261384a3c9 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-linear/llama_index/readers/linear/base.py:30
        response = requests.post(graphql_endpoint, json=payload, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #98c004bccb0acd60 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:66
        response = requests.post(url, headers=headers, data=json.dumps(data))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #4d5de5b78f014dda Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-macrometa-gdn/llama_index/readers/macrometa_gdn/base.py:76
                response = requests.put(next_url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a6082ce8802c168d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-make-com/llama_index/readers/make_com/base.py:47
        r = requests.post(webhook_url, json=json_dict)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #6ffe4487df478df0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-mangadex/llama_index/readers/mangadex/base.py:23
            manga_response = requests.get(
                f"{self.base_url}/manga", params={"title": title}
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #ad390c61c86ff897 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-mangadex/llama_index/readers/mangadex/base.py:43
            author_response = requests.get(
                f"{self.base_url}/author", params={"ids[]": [id]}
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a17d50570aa06aa4 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-mangadex/llama_index/readers/mangadex/base.py:56
            chapter_response = requests.get(
                f"{self.base_url}/manga/{manga_id}/feed",
                params={
                    "translatedLanguage[]": [lang],
                    "order[chapter]": "asc",
                },
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3d1b1c4958bb9165 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-mangoapps-guides/llama_index/readers/mangoapps_guides/base.py:46
                response = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #1943d5c0f7257fc1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-mangoapps-guides/llama_index/readers/mangoapps_guides/base.py:120
        response = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #29030f1d43c3c3ad Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-memos/llama_index/readers/memos/base.py:42
            req = requests.get(realUrl, params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0508bcabc0f24603 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-onedrive/llama_index/readers/microsoft_onedrive/base.py:235
            response = requests.get(endpoint, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #90379e468d008686 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-onedrive/llama_index/readers/microsoft_onedrive/base.py:273
        file_data = requests.get(file_download_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #6b5ff57fa52dbaee Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-onedrive/llama_index/readers/microsoft_onedrive/base.py:277
        with open(file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a6952e0cb3ae38b6 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-onedrive/llama_index/readers/microsoft_onedrive/base.py:858
            with open(local_file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #baf14180f29c9e5e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-outlook-emails/llama_index/readers/microsoft_outlook_emails/base.py:68
        response = requests.post(token_url, data=payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0410cd6647573053 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-outlook-emails/llama_index/readers/microsoft_outlook_emails/base.py:76
        response = requests.get(url, headers=self._authorization_headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #73bdd13c80dc39cd Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-sharepoint/llama_index/readers/microsoft_sharepoint/base.py:414
        response = requests.get(file_download_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #65bb76706db67a9c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-microsoft-sharepoint/llama_index/readers/microsoft_sharepoint/base.py:447
        with open(file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #530a3f59805a8c91 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-notion/llama_index/readers/notion/base.py:36
            integration_token = os.getenv(INTEGRATION_TOKEN_NAME)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #bc842efbed283b4a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-notion/llama_index/readers/notion/base.py:116
                response = requests.request(method, url, headers=headers, json=json)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #27427d1ed9570048 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:43
            response = requests.get(full_url, timeout=10)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #84c6f6e0be1e162f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-openalex/llama_index/readers/openalex/base.py:63
            response = requests.get(full_url, timeout=10)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #6335b828ef1c7410 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-opendal/llama_index/readers/opendal/base.py:73
        with open(filepath, "wb") as w:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #59c0f33dd325790e Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-oracleai/llama_index/readers/oracleai/base.py:134
            with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #ba0066693bda9004 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-papers/llama_index/readers/papers/pubmed/base.py:43
        resp = requests.get(
            "https://eutils.ncbi.nlm.nih.gov/entrez/eutils/esearch.fcgi",
            params=parameters,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #5602f292ae5ff91f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-papers/llama_index/readers/papers/pubmed/base.py:53
                    resp = requests.get(
                        f"https://www.ncbi.nlm.nih.gov/research/bionlp/RESTful/pmcoa.cgi/BioC_json/PMC{_id}/ascii"
                    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #b84d49a26efc1c68 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-papers/llama_index/readers/papers/pubmed/base.py:126
        resp = requests.get(
            "https://eutils.ncbi.nlm.nih.gov/entrez/eutils/esearch.fcgi",
            params=parameters,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8ac5b709ddbb2883 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-papers/llama_index/readers/papers/pubmed/base.py:138
                    resp = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #105e6b807131c8e4 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-patentsview/llama_index/readers/patentsview/base.py:38
            self.api_key = os.getenv("PATENTSVIEW_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #f2ab4db44151c8c3 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-patentsview/llama_index/readers/patentsview/base.py:65
        response = requests.post(BASE_URL, json=self.json, headers=self.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #751eafece92425f2 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-patentsview/llama_index/readers/patentsview/base.py:70
            response = requests.post(BASE_URL, json=self.json, headers=self.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #b1a8fb46c5670ab7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pathway/llama_index/readers/pathway/base.py:60
        response = requests.post(
            url,
            data=json.dumps(data),
            headers={"Content-Type": "application/json"},
            timeout=3,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e2964ffbc86e1d77 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pathway/llama_index/readers/pathway/base.py:74
        response = requests.post(
            url,
            json={},
            headers={"Content-Type": "application/json"},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #06f02a753d81cda7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pathway/llama_index/readers/pathway/base.py:98
        response = requests.post(
            url,
            json={
                "metadata_filter": metadata_filter,
                "filepath_globpattern": filepath_globpattern,
            },
            headers={"Content-Type": "application/json"},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #1bf2a9aeef8a10f1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pdb/llama_index/readers/pdb/utils.py:10
    pubmed_response = requests.get(pubmed_query)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #edc0a9953d8bea81 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pdb/llama_index/readers/pdb/utils.py:11
    entry_response = requests.get(entry_query)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #6b5126923fbfe26a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pdb/llama_index/readers/pdb/utils.py:38
    response = requests.get(f"{base_url}{pdb_id}")

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3105d67fdd5a74bf Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pebblo/llama_index/readers/pebblo/base.py:139
            resp = requests.post(
                load_doc_url, headers=headers, json=payload, timeout=20
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3b917279c1485cd3 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-pebblo/llama_index/readers/pebblo/base.py:184
            resp = requests.post(
                app_discover_url, headers=headers, json=payload, timeout=20
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #fb12add9c6dfe0de Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-pebblo/llama_index/readers/pebblo/utility.py:16
CLASSIFIER_URL = os.getenv("PEBBLO_CLASSIFIER_URL", "http://localhost:8000")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2e50d073ec202ac8 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-pebblo/llama_index/readers/pebblo/utility.py:212
        path=os.environ["PWD"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dbe81172128da00c Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-psychic/llama_index/readers/psychic/base.py:39
            psychic_key = os.environ["PSYCHIC_SECRET_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #6b613eb9a1978e9b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-quip/llama_index/readers/quip/base.py:80
                response = requests.request(method, url, headers=headers, json=json)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #2d5abf49a94162b1 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-reddit/llama_index/readers/reddit/base.py:35
            client_id=os.getenv("REDDIT_CLIENT_ID"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #eca1d8e2f4c21eb6 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-reddit/llama_index/readers/reddit/base.py:36
            client_secret=os.getenv("REDDIT_CLIENT_SECRET"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7e27bf9094ae57d5 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-reddit/llama_index/readers/reddit/base.py:37
            user_agent=os.getenv("REDDIT_USER_AGENT"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4eb52f55913979ad Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-reddit/llama_index/readers/reddit/base.py:38
            username=os.getenv("REDDIT_USERNAME"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #47e72bc53d190906 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-reddit/llama_index/readers/reddit/base.py:39
            password=os.getenv("REDDIT_PASSWORD"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0584b83dd075ac3d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-remote-depth/llama_index/readers/remote_depth/base.py:79
        page = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #c707296fc85dfd46 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-remote/llama_index/readers/remote/base.py:74
        result = urlopen(req)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #1ebb5a2dcf192091 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-remote/llama_index/readers/remote/base.py:88
                with open(filepath, "wb") as output:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #d627b85f99319a59 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-screenpipe/llama_index/readers/screenpipe/base.py:63
        response = requests.get(url, params=params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #f10b65b4d5ab6d0c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/base.py:86
                    with open(
                        f"data/{curr_tic}/{curr_year}/{curr_filing_type}.json", "w"
                    ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #99add615aecb9227 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/base.py:92
                    with open(
                        f"data/{curr_tic}/{curr_year[:-2]}/{curr_filing_type}_{curr_year[-2:]}.json",
                        "w",
                    ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b1b9815e5a9ad6e0 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/api/app.py:22
allowed_origins = os.environ.get("ALLOWED_ORIGINS", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e3aa87e162e60117 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/api/section.py:223
    allowed_mimetypes_str = os.environ.get("UNSTRUCTURED_ALLOWED_MIMETYPES")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #58c24e9a94a81aa0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/fetch.py:61
    response = session.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #885ae27702790c49 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/fetch.py:72
    response = session.get(url, stream=True)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #56b6c9b154b7c99d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/fetch.py:83
    response = session.get(f"{SEC_SUBMISSIONS_URL}/{json_name}")

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #ec4425eab976db90 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/fetch.py:252
        company = os.environ.get("SEC_API_ORGANIZATION")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d5b724639eda0e17 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/prepline_sec_filings/fetch.py:254
        email = os.environ.get("SEC_API_EMAIL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #d6cbd27e1bf1d887 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/sec_filings.py:332
        response = session.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #3fc8ac04c6f54d76 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/sec_filings.py:345
            company = os.environ.get("SEC_API_ORGANIZATION")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f1a247a13f485744 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/sec_filings.py:347
            email = os.environ.get("SEC_API_EMAIL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #8bbbba8fdad9485b Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-sec-filings/llama_index/readers/sec_filings/utils.py:146
            resp = client.post(
                SEC_EDGAR_SEARCH_API_ENDPOINT, json=payload, headers=headers
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #59f030a93119c503 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-semanticscholar/llama_index/readers/semanticscholar/base.py:57
        response = requests.get(url, headers=headers, stream=True)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #2f5d0e1ad23bc707 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-semanticscholar/llama_index/readers/semanticscholar/base.py:68
            with open(file_path, "wb") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ed5c65a1e19766f9 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-semanticscholar/llama_index/readers/semanticscholar/base.py:126
                    pdf = PdfReader(open(file_path, "rb"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5f714521be00a6f5 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-service-now/llama_index/readers/service_now/base.py:66
            with open(test_file, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0a1a0a22289e3ca0 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-service-now/llama_index/readers/service_now/base.py:147
            with open(custom_file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #bcd902bd0d13fced Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-service-now/llama_index/readers/service_now/base.py:208
            with open(custom_file_path, "w", encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0b381bb53cae3c28 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-service-now/llama_index/readers/service_now/base.py:379
            with open(test_file, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #472b2caa108188d9 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-slack/llama_index/readers/slack/base.py:62
            slack_token = os.environ["SLACK_BOT_TOKEN"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #eed471f2713243a9 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:75
    resp = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #4d6d499b7ca8ba59 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:87
        self._api_key = api_key or os.environ.get("STACKOVERFLOW_PAT")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7da5543586c1e3df Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:88
        self._team_name = team_name or os.environ.get("STACKOVERFLOW_TEAM_NAME")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c3eb4cfeb496b7d4 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:107
                    with open(fp) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2267dbd4f5ca8cf3 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:116
                    with open(
                        os.path.join(self._cache_dir, f"{doc_type}_{page}.json"), "w"
                    ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5e5c596b228706d2 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:170
        os.environ.get("STACKOVERFLOW_PAT"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8426e9e591141520 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-stackoverflow/llama_index/readers/stackoverflow/base.py:171
        os.environ.get("STACKOVERFLOW_TEAM_NAME"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #f11613db9360fbf3 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-stripe-docs/llama_index/readers/stripe_docs/base.py:33
        return urllib.request.urlopen(url).read()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #008225793f64fefb Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-uniprot/llama_index/readers/uniprot/base.py:372
        with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #23d8c5e8bda15b7c Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-uniprot/llama_index/readers/uniprot/base.py:400
        with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ca05b7362fb919b4 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:95
    elif env_key and env_key in os.environ and os.environ[env_key]:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d858ed2154746e52 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:96
        return os.environ[env_key]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #f193625e43a9c41a Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:171
            response = requests.post(
                LAYOUT_ANALYSIS_URL, headers=headers, files=files, data=options
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #23c026a504d3f6cd Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:356
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #140a4d99e41f0ef1 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:388
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #208868f794314769 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/base.py:408
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c8f87d9fc6ff7d97 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:88
    elif env_key and env_key in os.environ and os.environ[env_key]:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d13f3bf2a5a69a7b Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:89
        return os.environ[env_key]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #f063382e1d62d1b8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:187
            response = requests.post(
                self.base_url,
                headers=headers,
                files=files,
                data={
                    "ocr": self.ocr,
                    "model": self.model,
                    "output_formats": f"['{self.output_format}']",
                    "coordinates": self.coordinates,
                    "base64_encoding": f"{self.base64_encoding}",
                },
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #247e62711ad1ab15 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:381
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #677d3804e4a453d6 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:413
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fe95581e670d7f2d Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-upstage/llama_index/readers/upstage/document_parse.py:433
                    with open(file_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #dcc958bd97a77e58 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/agentql_web/base.py:65
            response = httpx.post(
                QUERY_DATA_ENDPOINT,
                headers=headers,
                json=payload,
                timeout=API_TIMEOUT_SECONDS,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #efa9d4775ab685e9 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/async_web/base.py:74
                    async with session.get(url) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3b3ab92913510c7c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/beautiful_soup_web/base.py:42
        page_link = requests.get(doc_link)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #897c3fdfc89085cc Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/beautiful_soup_web/base.py:70
        page_link = requests.get(doc_link)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #3cc8e6fc67ffb790 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/beautiful_soup_web/base.py:112
        page_link = requests.get(doc_link)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #ca00cf04082ace4a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/beautiful_soup_web/base.py:189
                page = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #cc632be72642f995 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/hyperbrowser_web/base.py:36
        api_key = api_key or os.getenv("HYPERBROWSER_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #b2424aebbf69feef Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/main_content_extractor/base.py:42
            response = requests.get(url).text

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #312fa2b28ef734cb Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:107
        response = requests.post(api_url, headers=headers, json=data)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #50cfcd695ed0305b Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/olostep_web/base.py:145
        response = requests.post(api_url, headers=headers, json=data)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #d2ff85d30eff8591 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/readability_web/base.py:136
            with open(path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #36e0a958c4d6a443 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/rss/base.py:55
            parsed = feedparser.parse(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #54b003cc0c4635fa Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/rss_news/base.py:86
                feed = feedparser.parse(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #7a605bae0266dc9a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/simple_web/base.py:73
                response = requests.get(url, headers=None, timeout=self._timeout)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #d04361291a42a9d7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/sitemap/base.py:33
        sitemap_url_request = httpx.get(sitemap_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2ab4b50ad80606ef Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-web/llama_index/readers/web/zenrows_web/base.py:270
        response = requests.get(
            self._base_url,
            params=params,
            headers=request_headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #2855ab999319f187 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-whisper/llama_index/readers/whisper/base.py:92
            with open(file_path_or_bytes, "rb") as audio_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #18010567a84b0c84 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-whisper/llama_index/readers/whisper/base.py:125
            with open(file_path_or_bytes, "rb") as audio_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #04768d6188cdfe18 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-wordlift/llama_index/readers/wordlift/base.py:81
            response = requests.post(
                self.endpoint, json={"query": query}, headers=self.headers
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #73719df9ab790193 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-wordlift/llama_index/readers/wordlift/base.py:236
            response = requests.get(content)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #185643a2b5e0fe41 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-wordlift/llama_index/readers/wordlift/base.py:277
                response = requests.get(text)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #48a10ffa20283ea4 Filesystem access.
repo/llama-index-integrations/readers/llama-index-readers-wordlift/llama_index/readers/wordlift/base.py:285
                with open(text) as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0c0712580a7b36c5 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-wordpress/llama_index/readers/wordpress/base.py:132
        response = requests.get(url, auth=auth)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #56b4ad93d56c7b76 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-zendesk/llama_index/readers/zendesk/base.py:86
        response = requests.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #df6e1d4ca3c29966 Environment-variable access.
repo/llama-index-integrations/readers/llama-index-readers-zulip/llama_index/readers/zulip/base.py:26
        zulip_token = os.environ.get("ZULIP_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #a7ba61b06dc31b87 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/readers/llama-index-readers-zyte-serp/llama_index/readers/zyte_serp/base.py:73
        results = self.client.get(serp_request)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #fed0ceb7244ce1a6 Filesystem access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-bm25/llama_index/retrievers/bm25/base.py:214
        with open(
            os.path.join(path, DEFAULT_PERSIST_FILENAME), "w", encoding=encoding
        ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7b3bd138831304c6 Filesystem access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-bm25/llama_index/retrievers/bm25/base.py:225
        with open(os.path.join(path, DEFAULT_PERSIST_FILENAME), encoding=encoding) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #67aa15400834bd7f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-galaxia/llama_index/retrievers/galaxia/base.py:66
        conn = http.client.HTTPSConnection(self.api_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #93c361b565987dfe Environment-variable access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-mongodb-atlas-bm25-retriever/llama_index/retrievers/mongodb_atlas_bm25_retriever/base.py:48
            if "MONGO_URI" not in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #71f6af32d07206a4 Environment-variable access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-mongodb-atlas-bm25-retriever/llama_index/retrievers/mongodb_atlas_bm25_retriever/base.py:54
                os.environ["MONGO_URI"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #4746a3e84758bd6a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-pathway/llama_index/retrievers/pathway/base.py:67
        response = requests.post(
            url,
            data=json.dumps(data),
            headers={"Content-Type": "application/json"},
            timeout=3,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #598a2c3017a04b19 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-pathway/llama_index/retrievers/pathway/base.py:82
        response = requests.post(
            url,
            json={},
            headers={"Content-Type": "application/json"},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f3e6250808d43c9c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-pathway/llama_index/retrievers/pathway/base.py:106
        response = requests.post(
            url,
            json={
                "metadata_filter": metadata_filter,
                "filepath_globpattern": filepath_globpattern,
            },
            headers={"Content-Type": "application/json"},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #9de6b3a5593aa007 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-tldw/llama_index/retrievers/tldw/base.py:74
        res = requests.post(
            f"{API_ENDPOINT}/search",
            headers=headers,
            json={
                "collection_id": self._collection_id,
                "search_term": query_bundle.query_str,
            },
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #acc60c7024099886 Environment-variable access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-videodb/llama_index/retrievers/videodb/base.py:32
            api_key = os.environ.get("VIDEO_DB_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3f5578e5d7d1b6a7 Environment-variable access.
repo/llama-index-integrations/retrievers/llama-index-retrievers-you/llama_index/retrievers/you/base.py:60
        self._api_key = api_key or os.getenv("YDC_API_KEY") or ""

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #7dc1b28e677cc9ad Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-you/llama_index/retrievers/you/base.py:145
                response = client.get(
                    _SEARCH_ENDPOINT,
                    params=params,
                    headers=headers,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2b3e1e76d955a860 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/retrievers/llama-index-retrievers-you/llama_index/retrievers/you/base.py:168
                response = await client.get(
                    _SEARCH_ENDPOINT,
                    params=params,
                    headers=headers,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #c3eff97b28868b08 Environment-variable access.
repo/llama-index-integrations/selectors/llama-index-selectors-notdiamond/llama_index/selectors/notdiamond/base.py:84
            output = OpenAI(model=model, api_key=os.getenv("OPENAI_API_KEY"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1fdc2f1b79d7747d Environment-variable access.
repo/llama-index-integrations/selectors/llama-index-selectors-notdiamond/llama_index/selectors/notdiamond/base.py:88
            output = Anthropic(model=model, api_key=os.getenv("ANTHROPIC_API_KEY"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b49ac84ea2d08aff Environment-variable access.
repo/llama-index-integrations/selectors/llama-index-selectors-notdiamond/llama_index/selectors/notdiamond/base.py:92
            output = Cohere(model=model, api_key=os.getenv("COHERE_API_KEY"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5f034c7e3a5012b9 Environment-variable access.
repo/llama-index-integrations/selectors/llama-index-selectors-notdiamond/llama_index/selectors/notdiamond/base.py:96
            output = MistralAI(model=model, api_key=os.getenv("MISTRALAI_API_KEY"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #634dc4108f1cc9f7 Environment-variable access.
repo/llama-index-integrations/selectors/llama-index-selectors-notdiamond/llama_index/selectors/notdiamond/base.py:100
            output = TogetherLLM(model=model, api_key=os.getenv("TOGETHERAI_API_KEY"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7f522848993022ba Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-agentql/llama_index/tools/agentql/agentql_rest_api_tool/base.py:54
        self._api_key = os.getenv("AGENTQL_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #df3e25ca65afba20 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-agentql/llama_index/tools/agentql/utils.py:83
            response = await client.post(
                EXTRACT_DATA_ENDPOINT,
                headers=headers,
                json=payload,
                timeout=timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #4addd359013683b2 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-aws-bedrock-agentcore/llama_index/tools/aws_bedrock_agentcore/utils.py:6
    return os.getenv("AWS_REGION") or os.getenv("AWS_DEFAULT_REGION") or "us-west-2"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #359655d7eeb682e6 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:87
        self.pool_management_endpoint: str = pool_management_endpoint or os.getenv(
            "AZURE_POOL_MANAGEMENT_ENDPOINT"
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #05ebf85bddca6e5c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:176
        response = requests.post(api_url, headers=headers, json=body)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #a5e41ba6f7ad1da1 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:192
                            with open(file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1981c6967b3cb1e6 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:231
            data = open(local_file_path, "rb")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #97736fd5c560dca7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:243
        response = requests.request("POST", api_url, headers=headers, files=files)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #36c6be0a137b92c8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:277
        response = requests.get(api_url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #770905e31765a281 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:281
            with open(local_file_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #86bfb0f091eb663b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-code-interpreter/llama_index/tools/azure_code_interpreter/base.py:301
        response = requests.get(api_url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #7ba451aa413ffc1c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-cv/llama_index/tools/azure_cv/base.py:39
        response = requests.post(
            f"{self.cv_url}?features={','.join(features)}&language={self.language}&api-version={self.api_version}",
            headers={"Ocp-Apim-Subscription-Key": self.api_key},
            json={"url": url},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #1afb2c1cec394832 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-azure-translate/llama_index/tools/azure_translate/base.py:32
        request = requests.post(
            ENDPOINT_BASE_URL,
            params={"api-version": "3.0", "to": language},
            headers=self.headers,
            json=[{"text": text}],
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e18c7547d2651c45 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-bing-search/llama_index/tools/bing_search/base.py:25
        response = requests.get(
            ENDPOINT_BASE_URL + endpoint,
            headers={"Ocp-Apim-Subscription-Key": self.api_key},
            params={"q": query, "mkt": self.lang, "count": self.results},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #38251c64f4a1d839 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-brave-search/llama_index/tools/brave_search/base.py:41
        response = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #41c9db7738e5bf6b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-brightdata/llama_index/tools/brightdata/base.py:59
        response = requests.post(
            self._endpoint, headers=self._headers, data=json.dumps(payload)
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #84a9293ae4ea83bd Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-brightdata/llama_index/tools/brightdata/base.py:117
        response = requests.post(
            self._endpoint, headers=self._headers, data=json.dumps(payload)
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #a6e1316df5375c97 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-brightdata/llama_index/tools/brightdata/base.py:124
        with open(output_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e69d1c238e3de9e5 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-brightdata/llama_index/tools/brightdata/base.py:308
        trigger_response = requests.post(
            "https://api.brightdata.com/datasets/v3/trigger",
            params={"dataset_id": dataset_id, "include_errors": True},
            headers=self._headers,
            json=[request_data],
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #ef0f477d8c92ab37 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-brightdata/llama_index/tools/brightdata/base.py:330
                snapshot_response = requests.get(
                    f"https://api.brightdata.com/datasets/v3/snapshot/{snapshot_id}",
                    params={"format": "json"},
                    headers=self._headers,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #1c9beadeecbf6edf Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-chatgpt-plugin/llama_index/tools/chatgpt_plugin/base.py:33
            response = requests.get(manifest_url).text

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #bad2ef6cb7bc4239 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:33
        elif os.environ["OPENAI_API_KEY"]:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f668140bcc28527f Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:34
            self.OAI_token = os.environ["OPENAI_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #2311c60e1595b2a8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:97
            response = requests.post(api_url, headers=headers, data=data, files=files)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #13414ee51a1f5109 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:104
                files = {"file": open(file, "rb")}

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #8f0324804d603a07 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:112
            response = requests.post(api_url, headers=headers, data=data, files=files)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #36d76775b5c00fd0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:137
        response = requests.post(api_url, headers=headers, data=data)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #64ba52bc6c60180f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-cogniswitch/llama_index/tools/cogniswitch/base.py:157
        response = requests.get(
            self.knowledge_status_endpoint,
            headers=self.headers,
            params=params,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #e7d6329c45bd9dc7 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-dappier/llama_index/tools/dappier/ai_recommendations/base.py:35
        self.api_key = api_key or os.environ.get("DAPPIER_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f14e9afe7b3200b0 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-dappier/llama_index/tools/dappier/real_time_search/base.py:22
        self.api_key = api_key or os.environ.get("DAPPIER_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3ff082fdddbaf6d6 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-elevenlabs/llama_index/tools/elevenlabs/base.py:107
        with open(output_path, "wb") as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #970a9bd7dea09eb1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-finance/llama_index/tools/finance/earnings.py:19
    response = requests.request(
        "GET",
        f"https://www.alphavantage.co/query?function=EARNINGS&symbol={symbol}&apikey={ALPHA_VANTAGE_API_KEY}",
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #0a1362c17a8058e9 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/calendar/base.py:179
            with open(self.service_account_key_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f205a0a716a9757b Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/calendar/base.py:202
                with open(self.token_path, "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5837e1c3402d1ad9 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/gmail/base.py:116
            with open(self.service_account_key_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #031429094edf284b Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/gmail/base.py:139
                with open(self.token_path, "w") as token:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #7f9310b296370609 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/search/base.py:70
            response = client.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #4fa98669bef4fd9e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-google/llama_index/tools/google/search/base.py:91
            response = await client.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #921c074bc3bde407 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-graphql/llama_index/tools/graphql/base.py:33
        res = requests.post(
            self.url,
            headers=self.headers,
            json={
                "query": query,
                "variables": variables,
                "operationName": operation_name,
            },
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #78ec833bb93fb0f2 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-jina/llama_index/tools/jina/base.py:32
        response = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #7dc7436b1418647e Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-jira-issue/llama_index/tools/jira_issue/base.py:25
        email: str = os.environ.get("JIRA_ACCOUNT_EMAIL", ""),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c9570468fccb90c0 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-jira-issue/llama_index/tools/jira_issue/base.py:26
        api_key: Optional[str] = os.environ.get("JIRA_API_KEY", ""),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a311d986aff5a745 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-jira-issue/llama_index/tools/jira_issue/base.py:27
        server_url: Optional[str] = os.environ.get("JIRA_SERVER_URL", ""),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #b61c6ea43903b608 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-mcp-discovery/llama_index/tools/mcp_discovery/base.py:60
                async with session.post(
                    self.api_url, json={"need": user_request, "limit": limit}
                ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #c08d0455a2f4351e Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-mcp/examples/mcp_server.py:38
        access_token=os.environ.get("IPINFO_API_TOKEN", None),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #cb4a6cf25ec46c95 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:10
    'hourly_weather': os.getenv('HOURLY_WEATHER_API_KEY'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #b717e6eac486a808 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:11
    'daily_weather': os.getenv('DAILY_WEATHER_API_KEY'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #6e8289c4b723c2c3 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:12
    'daily_climate': os.getenv('DAILY_CLIMATE_API_KEY'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #a421e8d05cab7b22 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:13
    'air_quality': os.getenv('AIR_QUALITY_API_KEY'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #c3e0615ddda3d3bd Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:14
    'geocoding': os.getenv('GEOCODING_API_KEY'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #39f1c76297c4d266 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:23 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:10 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:23
print(
    await agent.run("How's the temperature for New York in next 3 days?")
)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #e456149a234456ac PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:26 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:10 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-measurespace/examples/example.py:26
print(
    await agent.run("What's the latitude and longitude of New York?")
)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs test-only Excluded from app score #cbfaae4a4d52d934 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:14
    MOSS_PROJECT_KEY = os.getenv("MOSS_PROJECT_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #ae8824a157c7e36e Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:15
    MOSS_PROJECT_ID = os.getenv("MOSS_PROJECT_ID")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #29da5dfc1bc77fa3 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:55
    llm = OpenAI(api_key=os.environ["OPENAI_API_KEY"])

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #62269d87e7e4ded7 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:66 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:55 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:66
    print(response)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #d441287f1f71740c PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:72 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:55 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-moss/examples/moss_agent.py:72
    print(response)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low egress production #ea02ea103535bf6a Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-notion/llama_index/tools/notion/base.py:106
        response = requests.post(SEARCH_URL, json=payload, headers=self.reader.headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2c7bde73ac02847a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-openapi/llama_index/tools/openapi/base.py:35
            response = requests.get(url).text

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #193f657786cda79f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-parallel-web-systems/llama_index/tools/parallel_web_systems/base.py:112
                response = await client.post(
                    f"{self.base_url}/v1beta/search",
                    headers=headers,
                    json=payload,
                    timeout=60,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #680539901553f58f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-parallel-web-systems/llama_index/tools/parallel_web_systems/base.py:199
                response = await client.post(
                    f"{self.base_url}/v1beta/extract",
                    headers=headers,
                    json=payload,
                    timeout=60,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f1d60586c183d7fd Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-playgrounds/llama_index/tools/playgrounds/subgraph_connector/base.py:69
            response = requests.post(self.url, headers=self.headers, json=payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e0f007a403d774ab Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-playgrounds/llama_index/tools/playgrounds/subgraph_inspector/base.py:108
            response = requests.post(self.url, headers=self.headers, json=payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #361ece40ddea12f9 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-python-file/llama_index/tools/python_file/base.py:11
        f = open(file_name).read()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #2325ef6cf86d84c0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-requests/llama_index/tools/requests/base.py:56
        res = requests.get(
            url,
            headers=self._get_headers_for_url(url_template),
            params=query_params,
            timeout=self.timeout_seconds,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0f84f195fd523b7c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-requests/llama_index/tools/requests/base.py:86
        res = requests.post(
            url,
            headers=self._get_headers_for_url(url_template),
            params=query_params,
            json=body,
            timeout=self.timeout_seconds,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #db0162975c905257 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-requests/llama_index/tools/requests/base.py:148
        res = requests.put(
            url,
            headers=self._get_headers_for_url(url_template),
            params=query_params,
            json=body,
            timeout=self.timeout_seconds,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #b40cbed3ea32c4b3 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-serpex/examples/serpex_example.py:8
os.environ["SERPEX_API_KEY"] = "your_api_key_here"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #bb78fd5d69136022 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-serpex/examples/serpex_example.py:101
    if not os.environ.get("SERPEX_API_KEY"):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8aed0b4f7f2c88e5 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:55
        self.api_key = api_key or os.environ.get("SERPEX_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #9531235dcc589f2b Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-serpex/llama_index/tools/serpex/base.py:128
            response = requests.get(
                self.base_url,
                params=params,
                headers={
                    "Authorization": f"Bearer {self.api_key}",
                },
                timeout=30,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #f785ae62a4f0a4e5 Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-serpex/test_local.py:12
    api_key = os.environ.get("SERPEX_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #229e0693316b0f9b Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-signnow/llama_index/tools/signnow/base.py:22
    env = dict(os.environ)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c8512f3cb57ada6b Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-signnow/llama_index/tools/signnow/base.py:55
    candidate = explicit or os.environ.get("SIGNNOW_MCP_BIN") or "sn-mcp"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0b77e256eb7843e9 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-text-to-image/llama_index/tools/text_to_image/base.py:55
                image=BytesIO(requests.get(url).content).getvalue(), n=n, size=size

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #5f651687c9018b1d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-text-to-image/llama_index/tools/text_to_image/base.py:74
            plt.imshow(Image.open(BytesIO(requests.get(url).content)))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #00282a2e803dd8e7 Filesystem access.
repo/llama-index-integrations/tools/llama-index-tools-typecast/llama_index/tools/typecast/base.py:186
        with open(output_path, "wb") as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #109d4cd0d174481e Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:10
    api_key=os.environ["VALYU_API_KEY"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #05e39b17a623d03d PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:29 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:10 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:29
print(search_response)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #0120e87da4efe3ff PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:36 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:10 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/context.py:36
print(content_response)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs test-only Excluded from app score #b04b61235580c10f Environment-variable access.
repo/llama-index-integrations/tools/llama-index-tools-valyu/examples/retriever_example.py:18
        api_key=os.environ.get("VALYU_API_KEY", "your-api-key-here"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #be16acde5f4aca06 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-wolfram-alpha/llama_index/tools/wolfram_alpha/base.py:81
        response = requests.get(url, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #917b1c1a24b91c77 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-zapier/llama_index/tools/zapier/base.py:60
        response = requests.get(
            "https://nla.zapier.com/api/v1/dynamic/exposed/", headers=self._headers
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #11be28ccc18cca94 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/tools/llama-index-tools-zapier/llama_index/tools/zapier/base.py:66
        response = requests.post(
            ACTION_URL_TMPL.format(action_id=id),
            headers=self._headers,
            data=json.dumps(kwargs),
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #b617789b73ae9ed3 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-azurecosmosmongo/llama_index/vector_stores/azurecosmosmongo/base.py:111
            if "AZURE_COSMOSDB_MONGODB_URI" not in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #327a0b340a04d913 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-azurecosmosmongo/llama_index/vector_stores/azurecosmosmongo/base.py:117
                os.environ["AZURE_COSMOSDB_MONGODB_URI"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ee8a4ad48db01069 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-db2/llama_index/vector_stores/db2/base.py:44
log_level = os.getenv("LOG_LEVEL", "ERROR").upper()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #9f11395a4ab0bfc4 Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-docarray/llama_index/vector_stores/docarray/hnsw.py:72
            with open(ref_docs_path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #382b358ff4e1febf Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-docarray/llama_index/vector_stores/docarray/hnsw.py:123
        with open(os.path.join(self._work_dir, "ref_docs.json"), "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #cabb3ae43c8f5261 Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-faiss/llama_index/vector_stores/faiss/map_store.py:244
        with open(id_map_path, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0744647767341b1f Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-faiss/llama_index/vector_stores/faiss/map_store.py:284
        with open(id_map_path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4e4b0d15db2374c9 Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-hnswlib/llama_index/vector_stores/hnswlib/base.py:152
        with open(config_path) as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4eb4e87b59a0212b Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-hnswlib/llama_index/vector_stores/hnswlib/base.py:216
        with open(config_path, "w") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b0303bdae8abe9bc Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-jaguar/llama_index/vector_stores/jaguar/base.py:497
        with open("/tmp/debugjaguar.log", "a") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8aa225b3e0da7a11 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-lancedb/llama_index/vector_stores/lancedb/base.py:230
            if api_key is None and os.getenv("LANCE_API_KEY") is None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d702854994064bdb Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-lancedb/llama_index/vector_stores/lancedb/base.py:242
                    uri, api_key=api_key or os.getenv("LANCE_API_KEY"), region=region

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #53a9c598fccf4d2a Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-mongodb/llama_index/vector_stores/mongodb/base.py:188
            if "MONGODB_URI" not in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a571216aad1ffab5 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-mongodb/llama_index/vector_stores/mongodb/base.py:194
                os.environ["MONGODB_URI"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dda1508e5f646f83 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-mongodb/llama_index/vector_stores/mongodb/base.py:203
            if "MONGODB_URI" not in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #048881ef8654653f Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-mongodb/llama_index/vector_stores/mongodb/base.py:209
                os.environ["MONGODB_URI"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dad6874e1f5ae701 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-moorcheh/llama_index/vector_stores/moorcheh/base.py:103
            self.api_key = os.getenv("MOORCHEH_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2268157e11490510 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-oracledb/llama_index/vector_stores/oracledb/base.py:51
log_level = os.getenv("LOG_LEVEL", "ERROR").upper()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5b3150b5e8058666 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-rocksetdb/llama_index/vector_stores/rocksetdb/base.py:51
    elif not api_key and not getenv("ROCKSET_API_KEY"):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2ed5cc585456cd02 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-rocksetdb/llama_index/vector_stores/rocksetdb/base.py:57
            api_key=api_key or getenv("ROCKSET_API_KEY"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #cd6210509eec4515 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-rocksetdb/llama_index/vector_stores/rocksetdb/base.py:58
            host=api_server or getenv("ROCKSET_API_SERVER"),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7ef99bb51cf2872e Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-txtai/llama_index/vector_stores/txtai/base.py:125
        with open(config_path, "r" if jsonconfig else "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0e94159a604e0a59 Filesystem access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-txtai/llama_index/vector_stores/txtai/base.py:189
        with open(
            config_path,
            "w" if jsonconfig else "wb",
            encoding="utf-8" if jsonconfig else None,
        ) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #9a4486579f87aadc Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-vertexaivectorsearch/llama_index/vector_stores/vertexaivectorsearch/base.py:100
    ENABLE_V2 = os.getenv("VERTEX_AI_ENABLE_V2", "true").lower() == "true"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #0abf43d4a7ae70cc Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:26
EMBEDDING_MODEL = os.getenv("ARK_EMBEDDING_MODEL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #381b823492901ebd Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:30
LLM_MODEL = os.getenv("ARK_LLM_MODEL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #ab25aa901d618c23 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34
ARK_API_KEY = os.getenv("ARK_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #f48cf009a3a4ff16 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:141
    host = os.getenv("VEM_HOST")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #6cb349092cbb6473 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:142
    port = int(os.getenv("VEM_PORT")) if os.getenv("VEM_PORT") else None

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #2f96c1f8969c182b Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:143
    user = os.getenv("VEM_USER")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #0b0ad1135e41451d Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:144
    password = os.getenv("VEM_PASSWORD")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #be39684fe7225c7d Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:145
    database = os.getenv("VEM_DATABASE")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #717e585576357543 Environment-variable access.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:146
    table_name = os.getenv("VEM_TABLE", "llamaindex_demo")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low pii_flow test-only Excluded from app score #321068993d6b191f PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:237 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:237
    print(f"Top {len(result.nodes)} results:")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #120d4429709da90b PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:241 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:241
            print(f"  {i}. similarity={sim:.4f}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #83db110dd43bc72d PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:243 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:243
            print(f"  {i}.")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #cedf9b9ed355f737 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:245 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:245
        print(f"     metadata={node.metadata}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low pii_flow test-only Excluded from app score #48ad90ca1b56c655 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:261 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:34 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql/examples/volcengine_mysql_vector_store_demo.py:261
    print(answer)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

low env_fs production #9a0af653d51b827a Environment-variable access.
repo/llama-index-integrations/voice_agents/llama-index-voice-agents-openai/llama_index/voice_agents/openai/base.py:74
            openai_api_key = os.getenv("OPENAI_API_KEY", None) or self.api_key

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #8b7583b99dd5aaec Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-utils/llama-index-utils-huggingface/llama_index/utils/huggingface/base.py:85
        response = requests.get(pooling_config_url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #09693fd9700cd9ba Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-utils/llama-index-utils-qianfan/llama_index/utils/qianfan/apis.py:61
    resp_dict = client.post(url, json=json)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #2dc0e15955abdb75 Filesystem access.
repo/scripts/bulk-version-bump.py:26
    with open(path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #d8f7d2502ae4334d Filesystem access.
repo/scripts/bulk-version-bump.py:28
    with open(path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #62c1eee0b98fca94 Filesystem access.
repo/scripts/bulk-version-bump.py:81
    with open(path, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #096655c425896b46 Filesystem access.
repo/scripts/convert-examples.py:204
        out.write_text(body, encoding="utf-8")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #bc1f378fb186e952 Filesystem access.
repo/scripts/convert-examples.py:231
            meta.write_text(f"label: {transform_dir_name(d.name)}\ncollapsed: true\n")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #db1c44c88f6eb0e1 Filesystem access.
repo/scripts/convert-examples.py:259
    content = src.read_text(encoding="utf-8")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #dd093632ff3f6fb7 Filesystem access.
repo/scripts/convert-examples.py:263
    dst.write_text(content, encoding="utf-8")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #3d531cfc69e07fb0 Filesystem access.
repo/scripts/convert-examples.py:400
    (int_dest / "_meta.yml").write_text(
        "label: Integrations\ncollapsed: true\norder: 998\n"
    )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #5b879547143e4657 Filesystem access.
repo/scripts/integration_health_check.py:207
            with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #029bd98a886fedc0 Filesystem access.
repo/scripts/integration_health_check.py:273
            with open("./core_package_metrics.json") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #dc452311249b6b7d Filesystem access.
repo/scripts/integration_health_check.py:286
            with open("./core_package_metrics.json", "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #648b91b97d68aa70 Filesystem access.
repo/scripts/integration_health_check.py:366
        with open("./all_package_metrics.json") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #cf57eca840afa58d Filesystem access.
repo/scripts/integration_health_check.py:374
        with open("./all_package_metrics.json", "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/observability/llama-index-observability-otel

python first-party
medium telemetry production #915dab5f04852bc3 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/observability/llama-index-observability-otel/llama_index/observability/otel/base.py:13
from opentelemetry import context, propagate, trace

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #5b269d37aed4bd99 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/observability/llama-index-observability-otel/llama_index/observability/otel/base.py:14
from opentelemetry.sdk.resources import SERVICE_NAME, Resource

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a7bb4ed2d1b127b2 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/observability/llama-index-observability-otel/llama_index/observability/otel/base.py:15
from opentelemetry.sdk.trace import SpanProcessor, TracerProvider

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #2557f6012feed0df Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/observability/llama-index-observability-otel/llama_index/observability/otel/base.py:16
from opentelemetry.sdk.trace.export import (
    BatchSpanProcessor,
    ConsoleSpanExporter,
    SimpleSpanProcessor,
    SpanExporter,

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6855db5b85c13a07 Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/llama-index-integrations/observability/llama-index-observability-otel/llama_index/observability/otel/base.py:22
from opentelemetry.trace import set_span_in_context

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

first-party (python): llama-index-integrations/llms/llama-index-llms-maritalk

python first-party
medium pii_flow production #c30d2b5d98a9b833 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:204 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:202 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:204
        response = requests.post(self._endpoint, json=data, headers=headers)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #247349600339d57b A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:293 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:289 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:293
                self._endpoint, json=data, headers=headers, stream=True

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 4 low-confidence finding(s)
low env_fs production #fd75343fca2557b5 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:138
        self.api_key = self.api_key or os.getenv("MARITALK_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #ae9edff125370a74 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:204
        response = requests.post(self._endpoint, json=data, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #640001915ecce73e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:245
                response = await client.post(
                    self._endpoint, json=data, headers=headers, timeout=None
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e3588fdf473f5869 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-maritalk/llama_index/llms/maritalk/base.py:292
            response = requests.post(
                self._endpoint, json=data, headers=headers, stream=True
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-mymagic

python first-party
medium pii_flow production #156d28d65aceb631 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:196 · flow /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:190 → /tmp/closeopen-9d8z939w/repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:196
            headers=headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 4 low-confidence finding(s)
low egress production #9b8c339e29fc0726 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:147
            resp = await client.post(
                self.completion_url,
                json=question_data,
                headers=headers,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #86453cee4a1a859f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:159
            resp = await client.get(url)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0ab87b3756740ae8 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:193
        resp = requests.post(
            self.completion_url,
            json=question_data,
            headers=headers,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f4b1dd72ce82ddc1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-mymagic/llama_index/llms/mymagic/base.py:204
        response = requests.get(url, timeout=600.0)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-dev

python first-party
expand_more 9 low-confidence finding(s)
low env_fs production #9fa69adf9dbf7884 Environment-variable access.
repo/llama-dev/llama_dev/pkg/cmd_exec.py:44
    env = os.environ.copy()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #23a9f5afac28f3ea Filesystem access.
repo/llama-dev/llama_dev/release/changelog.py:84
    with open(repo_root / "CHANGELOG.md", "r+") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #77a8f60b5167b857 Filesystem access.
repo/llama-dev/llama_dev/release/check.py:20
    with open(repo_root / "llama-index-core" / "pyproject.toml", "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e233db1dc125bfef Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-dev/llama_dev/release/check.py:29
        with urllib.request.urlopen(url, timeout=10) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #c67bfd37bb420c29 Filesystem access.
repo/llama-dev/llama_dev/release/prepare.py:16
    with open(pyproject_path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #873088a550db6a87 Filesystem access.
repo/llama-dev/llama_dev/release/prepare.py:23
    with open(pyproject_path, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2773caae76f5f4d6 Filesystem access.
repo/llama-dev/llama_dev/utils.py:46
    with open(pyproject_path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d4abe41e0bc414f9 Filesystem access.
repo/llama-dev/llama_dev/utils.py:55
    with open(pyproject_path, "w") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3089257fc3a1b8cf Filesystem access.
repo/llama-dev/llama_dev/utils.py:74
    with open(pyproject_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-core

python first-party
expand_more 43 low-confidence finding(s)
low env_fs production #7b8800bb4557ca90 Environment-variable access.
repo/llama-index-core/llama_index/core/base/llms/generic_utils.py:320
    elif env_key and env_key in os.environ and os.environ[env_key]:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e5e6f24e4276a93b Environment-variable access.
repo/llama-index-core/llama_index/core/base/llms/generic_utils.py:321
        return os.environ[env_key]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0e30e366d7ba8139 Filesystem access.
repo/llama-index-core/llama_index/core/command_line/upgrade.py:119
    with open(mappings_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dcf47c0735bd5490 Filesystem access.
repo/llama-index-core/llama_index/core/command_line/upgrade.py:206
    with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #dc7b7f217ac1355a Filesystem access.
repo/llama-index-core/llama_index/core/command_line/upgrade.py:246
    with open(file_path, "w", encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1f2694483f908189 Filesystem access.
repo/llama-index-core/llama_index/core/command_line/upgrade.py:251
    with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e2554a129c42d396 Filesystem access.
repo/llama-index-core/llama_index/core/command_line/upgrade.py:257
    with open(file_path, "w", encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #16bf74a0ded06bfc Filesystem access.
repo/llama-index-core/llama_index/core/embeddings/utils.py:18
    with open(file_path, "w", encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1a7f1522fcd993e6 Filesystem access.
repo/llama-index-core/llama_index/core/embeddings/utils.py:24
    with open(file_path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #416c62b6c5d16bb6 Environment-variable access.
repo/llama-index-core/llama_index/core/embeddings/utils.py:43
        if os.getenv("IS_TESTING"):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress test-only Excluded from app score #affd7247d6fdfa6f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/evaluation/benchmarks/hotpotqa.py:38
                response = requests.get(url, stream=True)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs test-only Excluded from app score #3c89a38a998795fb Filesystem access.
repo/llama-index-core/llama_index/core/evaluation/benchmarks/hotpotqa.py:44
                with open(
                    os.path.join(dataset_full_path, "dev_distractor.json"), "wb"
                ) as save_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs test-only Excluded from app score #b3c924ea48b84fcb Filesystem access.
repo/llama-index-core/llama_index/core/evaluation/benchmarks/hotpotqa.py:76
        with open(dataset_path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #708b588446f5ec38 Filesystem access.
repo/llama-index-core/llama_index/core/evaluation/dataset_generation.py:102
        with open(path, "w", encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #69333d97c0b94372 Filesystem access.
repo/llama-index-core/llama_index/core/evaluation/dataset_generation.py:108
        with open(path, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2f5aefc29275b78a Environment-variable access.
repo/llama-index-core/llama_index/core/evaluation/retrieval/metrics.py:444
            api_key = api_key or os.environ["COHERE_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #758a049f008a816f Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:24
    base_url = base_url or os.environ.get("LLAMA_CLOUD_BASE_URL", DEFAULT_BASE_URL)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #01f0e3fddfd8dcc7 Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:25
    app_url = app_url or os.environ.get("LLAMA_CLOUD_APP_URL", DEFAULT_APP_URL)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b756566e001ac6df Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:26
    api_key = api_key or os.environ.get("LLAMA_CLOUD_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e6a1a8716d21a6a9 Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:43
    base_url = base_url or os.environ.get("LLAMA_CLOUD_BASE_URL", DEFAULT_BASE_URL)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #41d8ad5aa64df90b Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:44
    app_url = app_url or os.environ.get("LLAMA_CLOUD_APP_URL", DEFAULT_APP_URL)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f2bb6b443e8189af Environment-variable access.
repo/llama-index-core/llama_index/core/ingestion/api_utils.py:45
    api_key = api_key or os.environ.get("LLAMA_CLOUD_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c7562b6c241a2935 Environment-variable access.
repo/llama-index-core/llama_index/core/llms/utils.py:42
        if os.getenv("IS_TESTING"):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #4262b5f55f34cdeb Filesystem access.
repo/llama-index-core/llama_index/core/multi_modal_llms/generic_utils.py:44
    with open(image_path, "rb") as image_file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #bf46d26c76e5d745 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/multi_modal_llms/generic_utils.py:79
            response = requests.get(image_document.image_url, timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #b0bff22442f819ef Filesystem access.
repo/llama-index-core/llama_index/core/objects/base_node_mapping.py:204
            with open(obj_node_mapping_path, "wb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a399bc54c6b7b22c Filesystem access.
repo/llama-index-core/llama_index/core/objects/base_node_mapping.py:217
            with open(obj_node_mapping_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0314ab160c6415ce Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/query_engine/cogniswitch_query_engine.py:44
        response = requests.post(
            self.knowledge_request_endpoint,
            headers=self.headers,
            data=data,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #579c8ce92c8c114e Filesystem access.
repo/llama-index-core/llama_index/core/readers/json.py:102
            with open(input_file, encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #a1a50bc11c791771 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/response/notebook_utils.py:128
            img_response = requests.get(img_node.image_url, timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #b2a52cf572d35b5f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/schema.py:908
            response = requests.get(self.image_url, timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #7c76572b9e498472 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/schema.py:1320
        response = requests.get(url, stream=True, timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #2359f9659ec39b58 Filesystem access.
repo/llama-index-core/llama_index/core/schema.py:1433
            img_bytes = self.image_resource.path.read_bytes()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #b3ae0d5b7de635c0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/schema.py:1439
            response = requests.get(str(self.image_resource.url), timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #048826ddb2c36262 Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:56
        if "NLTK_DATA" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3a6eda50b3aff3fe Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:57
            self._nltk_data_dir = str(Path(os.environ["NLTK_DATA"]))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e7fbdc2bb9d1775f Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:167
        if "TIKTOKEN_CACHE_DIR" not in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e29e5856b554d960 Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:169
            os.environ["TIKTOKEN_CACHE_DIR"] = os.path.join(

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c83d2942e4fa1578 Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:179
            del os.environ["TIKTOKEN_CACHE_DIR"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #630c1557195ffbc3 Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:442
    if "LLAMA_INDEX_CACHE_DIR" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a07a755b8ee7c58e Environment-variable access.
repo/llama-index-core/llama_index/core/utils.py:443
        path = Path(os.environ["LLAMA_INDEX_CACHE_DIR"])

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #087327c67251529a Filesystem access.
repo/llama-index-core/llama_index/core/utils.py:664
        data = path.read_bytes()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #4a6afc9490aedafd Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-core/llama_index/core/utils.py:704
        response = requests.get(url, headers=headers, timeout=(60, 60))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/graph_stores/llama-index-graph-stores-nebula

python first-party
expand_more 4 low-confidence finding(s)
low env_fs production #0bf795d04ee2112f Environment-variable access.
repo/llama-index-integrations/graph_stores/llama-index-graph-stores-nebula/llama_index/graph_stores/nebula/nebula_graph_store.py:213
            key in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #f20f65ebadba7d77 Environment-variable access.
repo/llama-index-integrations/graph_stores/llama-index-graph-stores-nebula/llama_index/graph_stores/nebula/nebula_graph_store.py:221
        graphd_host, graphd_port = os.environ["NEBULA_ADDRESS"].split(":")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #33c8e3643568f856 Environment-variable access.
repo/llama-index-integrations/graph_stores/llama-index-graph-stores-nebula/llama_index/graph_stores/nebula/nebula_graph_store.py:223
            os.environ["NEBULA_USER"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #80b48c855c76144f Environment-variable access.
repo/llama-index-integrations/graph_stores/llama-index-graph-stores-nebula/llama_index/graph_stores/nebula/nebula_graph_store.py:224
            os.environ["NEBULA_PASSWORD"],

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-aibadgr

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #7884ff645e8e76f7 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-aibadgr/llama_index/llms/aibadgr/base.py:41
        api_key = api_key or os.environ.get("AIBADGR_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #6eb73c78141fd2c3 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-aibadgr/llama_index/llms/aibadgr/base.py:42
        api_base = os.environ.get("AIBADGR_BASE_URL", api_base)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-asi

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #d4dc141009ee376b Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-asi/llama_index/llms/asi/base.py:65
        api_key = api_key or os.environ.get("ASI_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-azure-openai

python first-party
expand_more 3 low-confidence finding(s)
low env_fs production #3475b9e1254c908e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-azure-openai/llama_index/llms/azure_openai/base.py:236
            self.api_key = self.api_key or os.getenv("AZURE_OPENAI_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3df481f7e4b0abe3 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-azure-openai/llama_index/llms/azure_openai/responses.py:141
            api_key = api_key or os.getenv("AZURE_OPENAI_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #98f5dffe276c8f50 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-azure-openai/llama_index/llms/azure_openai/responses.py:223
            self.api_key = self.api_key or os.getenv("AZURE_OPENAI_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-baseten

python first-party
expand_more 1 low-confidence finding(s)
low egress production #74b5c49085d0bb04 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-baseten/llama_index/llms/baseten/base.py:201
            async with session.post(
                DEFAULT_ASYNC_API_BASE.format(model_id=self.model),
                headers=headers,
                json=payload,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-cerebras

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #4be7dfc6d5a63685 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cerebras/llama_index/llms/cerebras/base.py:32
        api_base: str = os.environ.get("CEREBRAS_BASE_URL", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #edfe2175625edfe2 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cerebras/llama_index/llms/cerebras/base.py:37
        api_key = api_key or os.environ.get("CEREBRAS_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-clarifai

python first-party
expand_more 3 low-confidence finding(s)
low env_fs production #b18a6db77c9c7a4a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-clarifai/llama_index/llms/clarifai/base.py:83
        if pat is None and os.environ.get("CLARIFAI_PAT") is not None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #95f75c846f7af098 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-clarifai/llama_index/llms/clarifai/base.py:84
            pat = os.environ.get("CLARIFAI_PAT")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8d604c05c38842bc Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-clarifai/llama_index/llms/clarifai/base.py:86
        if not pat and os.environ.get("CLARIFAI_PAT") is None:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-cloudflare-ai-gateway

python first-party
expand_more 1 low-confidence finding(s)
low egress production #395bd59e907670f7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cloudflare-ai-gateway/llama_index/llms/cloudflare_ai_gateway/base.py:325
            response = client.post(url, json=request_body, headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-cortex

python first-party
expand_more 20 low-confidence finding(s)
low env_fs production #78b8b2b3758516fa Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:111
        default=os.environ.get("SNOWFLAKE_USERNAME", None),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0b149a881ed01b73 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:115
        default=os.environ.get("SNOWFLAKE_ACCOUNT", None),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7d7c3189b67068ee Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:119
        default=os.environ.get("SNOWFLAKE_KEY_FILE", None),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #afc14e716dd439f9 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:172
        self.user = user or os.environ.get("SNOWFLAKE_USERNAME")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b5777f0a76f7c97b Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:173
        self.account = account or os.environ.get("SNOWFLAKE_ACCOUNT")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0d18beb68deb0f19 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:177
        env_key_file = os.environ.get("SNOWFLAKE_KEY_FILE")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ac522e0132089b84 Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:184
                with open(jwt_token) as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #9564ebdfe13d00b0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:276
        api_response = requests.post(
            **self._make_completion_payload(prompt, formatted, **kwargs), stream=True
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #7d88e440386c6165 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:297
            api_response = await session.post(
                **self._make_completion_payload(prompt, formatted, **kwargs)
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #cd72eb4ea69f6b10 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:321
        api_response = requests.post(
            **self._make_completion_payload(prompt, formatted, **kwargs), stream=True
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8ff656386f96c425 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:349
                api_response = await session.post(
                    **self._make_completion_payload(prompt, formatted, **kwargs)
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #68d0ce3372661258 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:365
                api_response = await session.post(
                    **self._make_completion_payload(prompt, formatted, **kwargs)
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #617228206ce98952 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:430
        api_response = requests.post(
            **self._make_chat_payload(messages, **kwargs), stream=True
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #cb78bf5a006a9c86 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:456
            api_response = await session.post(
                **self._make_chat_payload(messages, **kwargs)
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #647cf55adf51929d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:484
        api_response = requests.post(
            **self._make_chat_payload(messages, **kwargs), stream=True
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #0e7d3a1aea63f746 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/base.py:515
            api_response = await session.post(
                **self._make_chat_payload(messages, **kwargs)
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #44a6f2236922ca86 Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/utils.py:22
    with open(SPCS_TOKEN_PATH) as fp:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3911b37be2bcadab Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/utils.py:32
        os.path.exists(SPCS_TOKEN_PATH) and os.environ.get("SNOWFLAKE_HOST") is not None

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #488169967b018fcb Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/utils.py:45
    return os.getenv("SNOWFLAKE_HOST")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7149c5c5a9fdce13 Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-cortex/llama_index/llms/cortex/utils.py:61
    with open(sf_private_key_filepath, "rb") as pem_in:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-databricks

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #aaa8b4b1ab928bd5 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-databricks/llama_index/llms/databricks/base.py:36
        api_key = api_key or os.environ.get("DATABRICKS_TOKEN", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1c0bc38e3a8edcaa Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-databricks/llama_index/llms/databricks/base.py:37
        api_base = api_base or os.environ.get("DATABRICKS_SERVING_ENDPOINT", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-deepinfra

python first-party
expand_more 7 low-confidence finding(s)
low egress production #11435162c8f37be9 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/base.py:184
        result = self._client.request(INFERENCE_ENDPOINT, payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #018bd7d21121966e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/base.py:225
        result = self._client.request(CHAT_API_ENDPOINT, payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #df98bc50ad024c7a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/client.py:47
            response = requests.post(
                self.get_url(endpoint),
                json={
                    **payload,
                    "stream": False,
                },
                headers=self._get_headers(),
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #6abf6bc3b59c3362 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/client.py:77
            response = requests.post(
                self.get_url(endpoint),
                json={
                    **payload,
                    "stream": True,
                },
                headers=self._get_headers(),
                stream=True,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #d2d775337166e610 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/client.py:111
                async with session.post(
                    self.get_url(endpoint),
                    json={
                        **payload,
                        "stream": False,
                    },
                    headers=self._get_headers(),
                    timeout=self.timeout,
                ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #c88c20519a6ef848 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/client.py:142
                async with session.post(
                    self.get_url(endpoint),
                    json={
                        **payload,
                        "stream": True,
                    },
                    headers=self._get_headers(),
                    timeout=self.timeout,
                ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #d379c16f36ebf5ac Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-deepinfra/llama_index/llms/deepinfra/client.py:176
        return requests.get(request_url, headers=self._get_headers())

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-deepseek

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #f32ca021b38c5d9f Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-deepseek/llama_index/llms/deepseek/base.py:36
        api_key = api_key or os.environ.get("DEEPSEEK_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-featherlessai

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #a2a89148028a9aa6 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-featherlessai/llama_index/llms/featherlessai/base.py:37
        api_key = api_key or os.environ.get("FEATHERLESS_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-gaudi

python first-party
expand_more 10 low-confidence finding(s)
low env_fs test-only Excluded from app score #0133aac4e569459b Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/examples/basic.py:301
    args.quant_config = os.getenv("QUANT_CONFIG", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #69b6733e926bcf90 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:98
    args.local_rank = int(os.getenv("LOCAL_RANK", "0"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #2f417b78edb25095 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:99
    args.world_size = int(os.getenv("WORLD_SIZE", "0"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #707dc8ae57fa9bba Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:100
    args.global_rank = int(os.getenv("RANK", "0"))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d248b2041d9be40e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:113
        const_marking = os.getenv("ENABLE_CONST_MARKING", "True")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #8852b81b07fdc683 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:135
    os.environ.setdefault("EXPERIMENTAL_WEIGHT_SHARING", "FALSE")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #36352132d0a380d8 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:138
        os.environ.setdefault("GRAPH_VISUALIZATION", "true")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #3400bbefb0eb66bb Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:142
        os.environ.setdefault("PT_HPU_LAZY_ACC_PAR_MODE", "0")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #ab15a6de3e9f27b3 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:143
        os.environ.setdefault("PT_HPU_ENABLE_LAZY_COLLECTIVES", "true")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #0e68e20db65bea71 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-gaudi/llama_index/llms/gaudi/utils.py:153
        os.environ.setdefault("PT_HPUGRAPH_DISABLE_TENSOR_CACHE", "1")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-google-genai

python first-party
expand_more 4 low-confidence finding(s)
low env_fs production #3f45e6dff5fb71d1 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-google-genai/llama_index/llms/google_genai/base.py:199
        api_key = api_key or os.getenv("GOOGLE_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #15e6a6834644ca1e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-google-genai/llama_index/llms/google_genai/base.py:202
            or os.getenv("GOOGLE_GENAI_USE_VERTEXAI", "false") != "false"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #51f8900d8c452e0a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-google-genai/llama_index/llms/google_genai/base.py:204
        project = (vertexai_config or {}).get("project") or os.getenv(
            "GOOGLE_CLOUD_PROJECT", None
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #955814cd26a81c63 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-google-genai/llama_index/llms/google_genai/base.py:207
        location = (vertexai_config or {}).get("location") or os.getenv(
            "GOOGLE_CLOUD_LOCATION", None
        )

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-groq

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #2b8fbefdd7400f66 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-groq/llama_index/llms/groq/base.py:37
        api_key = api_key or os.environ.get("GROQ_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-huggingface

python first-party
expand_more 2 low-confidence finding(s)
low egress production #654d4987b1423c37 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-huggingface/llama_index/llms/huggingface/utils.py:11
    model_info = dict(requests.get(url).json())

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #2d63dc9b8ca25141 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-huggingface/llama_index/llms/huggingface/utils.py:21
    model_info = dict(requests.get(url).json())

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-ibm

python first-party
expand_more 9 low-confidence finding(s)
low env_fs production #6061d81ee36b6a75 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:38
        if not (apikey or "WATSONX_APIKEY" in os.environ) and not (

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #024162b349a76f5e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:39
            token or "WATSONX_TOKEN" in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fc06d8f3f6af0c07 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:49
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #84f563cee94e140c Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:60
            and "WATSONX_TOKEN" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c3f0b84a5ac5dc8a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:62
            and "WATSONX_PASSWORD" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #a8f4c558267782d4 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:64
            and "WATSONX_APIKEY" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #713bd902d4442781 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:74
        elif token or "WATSONX_TOKEN" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d3e770bb7863455e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:79
        elif password or "WATSONX_PASSWORD" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #b07112ad60c25279 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ibm/llama_index/llms/ibm/utils.py:88
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-keywordsai

python first-party
expand_more 2 low-confidence finding(s)
low egress production #3abba6252530c073 Hardcoded external endpoint. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-keywordsai/llama_index/llms/keywordsai/utils.py:50
        response = requests.get("https://api.keywordsai.co/api/models/public")

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #711fe75d1b10c5e9 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-keywordsai/llama_index/llms/keywordsai/utils.py:166
    openai_api_key = api_key or os.environ.get("KEYWORDSAI_API_KEY", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-llama-cpp

python first-party
expand_more 2 low-confidence finding(s)
low egress production #fbba67cca1480a69 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-llama-cpp/llama_index/llms/llama_cpp/base.py:231
            with requests.get(model_url, stream=True) as r:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #d616f1fd2f2c337a Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-llama-cpp/llama_index/llms/llama_cpp/base.py:232
                with open(model_path, "wb") as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-meta

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #361195039078021f Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-meta/llama_index/llms/meta/base.py:42
        api_key = api_key or os.environ.get("LLAMA_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-minimax

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #f940f067d9a039af Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-minimax/llama_index/llms/minimax/base.py:43
        api_key = api_key or os.environ.get("MINIMAX_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-modelslab

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #2da41ef1703f27a6 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-modelslab/llama_index/llms/modelslab/base.py:68
        api_key = api_key or os.environ.get("MODELSLAB_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-monsterapi

python first-party
expand_more 1 low-confidence finding(s)
low egress production #1f74527f266d2ce3 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-monsterapi/llama_index/llms/monsterapi/base.py:136
        response = requests.get(f"{api_base}/models/info", headers=headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-nebius

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #9f33db5419a9fe5b Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-nebius/llama_index/llms/nebius/base.py:42
        api_key = api_key or os.environ.get("NEBIUS_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-netmind

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #ad2bdde710b2688e Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-netmind/llama_index/llms/netmind/base.py:39
        api_key = api_key or os.environ.get("NETMIND_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-nvidia

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #3a04334abd88ea04 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-nvidia/llama_index/llms/nvidia/base.py:52
        base_url: Optional[str] = os.getenv("NVIDIA_BASE_URL", BASE_URL),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-nvidia-tensorrt

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #1c5898f6102fb4f8 Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-nvidia-tensorrt/llama_index/llms/nvidia_tensorrt/base.py:182
                with open(config_path) as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #caf719fa57809713 Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-nvidia-tensorrt/llama_index/llms/nvidia_tensorrt/base.py:245
                with open(serialize_path, "rb") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-oci-data-science

python first-party
expand_more 2 low-confidence finding(s)
low egress production #e4b98f7e1e874c0e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-oci-data-science/llama_index/llms/oci_data_science/client.py:427
            response = self._client.post(
                url,
                headers=self._prepare_headers(stream=False, headers=headers),
                auth=self.auth,
                json=payload,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #70e586066bd30b21 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-oci-data-science/llama_index/llms/oci_data_science/client.py:649
            response = await self._client.post(
                url,
                headers=self._prepare_headers(stream=False, headers=headers),
                auth=self.auth,
                json=payload,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-oci-genai

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #6bd84dab28ccc09f Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-oci-genai/llama_index/llms/oci_genai/utils.py:141
                with open(oci_config.get("security_token_file"), encoding="utf-8") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-openai

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #d01e050dc12b4c7b Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-openai/llama_index/llms/openai/utils.py:1042
    openai_api_key = api_key or os.environ.get("OPENAI_API_KEY", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-ovhcloud

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #84506aeb7b0f251a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-ovhcloud/llama_index/llms/ovhcloud/base.py:109
            api_key = os.environ.get("OVHCLOUD_API_KEY", "")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-paieas

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #8883d1d1ea6e04ed Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-paieas/llama_index/llms/paieas/base.py:24
        api_key = api_key or os.environ.get("PAIEAS_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fb733d8fa6fbd828 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-paieas/llama_index/llms/paieas/base.py:25
        api_base = api_base or os.environ.get("PAIEAS_API_BASE", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-palm

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #d341c17768137027 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-palm/llama_index/llms/palm/base.py:86
        api_key = api_key or os.environ.get("PALM_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-perplexity

python first-party
expand_more 9 low-confidence finding(s)
low env_fs production #e1d05ae4189d5065 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:118
        api_key = api_key or getenv("PPLX_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #e4f2da6472406a1c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:199
        response = requests.post(
            url, json=payload, headers=self.headers, timeout=self.timeout
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #5b917a06d164bd70 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:226
        response = requests.post(
            url, json=payload, headers=self.headers, timeout=self.timeout
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #c84c7e67f73b3140 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:256
            response = await client.post(
                url, json=payload, headers=self.headers, timeout=self.timeout
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #980c1b68202e4be6 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:287
            response = await client.post(
                url, json=payload, headers=self.headers, timeout=self.timeout
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #be69136f87c74a58 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:321
            response = requests.post(
                url,
                json=payload,
                headers=self.headers,
                stream=True,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #b654519a25115811 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:377
                response = await session.post(
                    url, json=payload, headers=self.headers, timeout=self.timeout
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #bda3ccc4ec5bd95f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:427
            response = requests.post(
                url,
                json=payload,
                headers=self.headers,
                stream=True,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a4a7a536f6a2298a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-perplexity/llama_index/llms/perplexity/base.py:483
                response = await session.post(
                    url, json=payload, headers=self.headers, timeout=self.timeout
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-pipeshift

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #1df647c526287168 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-pipeshift/llama_index/llms/pipeshift/base.py:64
        api_key = api_key or os.environ.get("PIPESHIFT_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-predibase

python first-party
expand_more 2 low-confidence finding(s)
low env_fs production #37f6bd12c2e05082 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-predibase/llama_index/llms/predibase/base.py:121
            else os.environ.get("PREDIBASE_API_TOKEN")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #d32c74ba361e2849 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-predibase/llama_index/llms/predibase/base.py:166
            os.environ["PREDIBASE_GATEWAY"] = "https://api.app.predibase.com"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-qianfan

python first-party
expand_more 1 low-confidence finding(s)
low egress production #609622cf79db65e1 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-qianfan/llama_index/llms/qianfan/base.py:300
        resp_dict = self._client.post(self.endpoint_url, json=request.dict())

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-reka

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #eea9dce5db9cf46a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-reka/llama_index/llms/reka/base.py:117
        api_key = api_key or os.getenv("REKA_API_KEY")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-replicate

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #6a219f25356c79be Filesystem access.
repo/llama-index-integrations/llms/llama-index-llms-replicate/llama_index/llms/replicate/base.py:97
                base_kwargs["image"] = open(self.image, "rb")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-rungpt

python first-party
expand_more 4 low-confidence finding(s)
low egress production #3a44b352ff0228b3 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-rungpt/llama_index/llms/rungpt/base.py:131
        response_gpt = requests.post(
            self.base_url + "/generate",
            json=self._request_pack("complete", prompt, **kwargs),
            stream=False,
        ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #8c42fd500f2565a6 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-rungpt/llama_index/llms/rungpt/base.py:154
        response_gpt = requests.post(
            self.base_url + "/generate_stream",
            json=self._request_pack("complete", prompt, **kwargs),
            stream=True,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #9908d0812f516a30 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-rungpt/llama_index/llms/rungpt/base.py:195
        response_gpt = requests.post(
            self.base_url + "/chat",
            json=self._request_pack("chat", message_list, **kwargs),
            stream=False,
        ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #6bdc5169fce2a236 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-rungpt/llama_index/llms/rungpt/base.py:215
        response_gpt = requests.post(
            self.base_url + "/chat_stream",
            json=self._request_pack("chat", message_list, **kwargs),
            stream=True,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-sambanovasystems

python first-party
expand_more 7 low-confidence finding(s)
low egress production #b0420812c40d5a0a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:255
        response = http_session.post(
            self.sambanova_url,
            headers={
                "Authorization": f"Bearer {self.sambanova_api_key.get_secret_value()}",
                "Content-Type": "application/json",
            },
            json=data,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #550234b9d87a062f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:302
            async with session.post(
                self.sambanova_url,
                headers={
                    "Authorization": f"Bearer {self.sambanova_api_key.get_secret_value()}",
                    "Content-Type": "application/json",
                },
                json=data,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #a203fdeccb147f2c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:355
        response = http_session.post(
            self.sambanova_url,
            headers={
                "Authorization": f"Bearer {self.sambanova_api_key.get_secret_value()}",
                "Content-Type": "application/json",
            },
            json=data,
            stream=True,
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #e0cf23d8d58fea6a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:433
            async with session.post(
                self.sambanova_url,
                headers={
                    "Authorization": f"Bearer {self.sambanova_api_key.get_secret_value()}",
                    "Content-Type": "application/json",
                },
                json=data,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #cac5ff19c546c28a Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:1033
            response = http_session.post(
                self.streaming_url, headers=headers, json=data, stream=True
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #94afce3345ea895d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:1037
            response = http_session.post(
                self.base_url, headers=headers, json=data, stream=False
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #4d25066f96cad4f7 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sambanovasystems/llama_index/llms/sambanovasystems/base.py:1146
            async with session.post(
                url,
                headers=headers,
                json=data,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-sglang

python first-party
expand_more 1 low-confidence finding(s)
low egress production #eed0bacd7dfbdd1e Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-sglang/llama_index/llms/sglang/utils.py:46
    return requests.post(
        api_url,
        headers=headers,
        json=sampling_params,
        stream=stream,
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-siliconflow

python first-party
expand_more 4 low-confidence finding(s)
low egress production #fe09eab5c12b791d Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-siliconflow/llama_index/llms/siliconflow/base.py:389
            response = session.post(
                self.base_url,
                json=input_json,
                headers=self._headers,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #76b7953c0ad4d961 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-siliconflow/llama_index/llms/siliconflow/base.py:425
            async with session.post(
                self.base_url,
                json=input_json,
                headers=self._headers,
                timeout=self.timeout,
            ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #96da9dfd238abec0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-siliconflow/llama_index/llms/siliconflow/base.py:462
                response = session.post(
                    self.base_url,
                    json=input_json,
                    headers=self._headers,
                    timeout=self.timeout,
                )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #67bf04e754be2f17 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-siliconflow/llama_index/llms/siliconflow/base.py:513
                async with session.post(
                    self.base_url,
                    json=input_json,
                    headers=self._headers,
                    timeout=self.timeout,
                ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-together

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #7fa86e28404bd4ad Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-together/llama_index/llms/together/base.py:39
        api_key = api_key or os.environ.get("TOGETHER_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-vllm

python first-party
expand_more 2 low-confidence finding(s)
low egress production #7a16f8ad8b6a6ebf Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-vllm/llama_index/llms/vllm/utils.py:24
    response = requests.post(
        api_url,
        headers=base_headers,
        json=sampling_params,
        stream=stream,
        timeout=timeout,
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #f90efb47aec0072c Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-vllm/llama_index/llms/vllm/utils.py:56
    response = requests.post(
        api_url, headers=base_headers, json=payload, stream=stream, timeout=timeout
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/llms/llama-index-llms-yi

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #db860ff1a53c8817 Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-yi/llama_index/llms/yi/base.py:90
        api_key = api_key or os.environ.get("YI_API_KEY", None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/llms/llama-index-llms-you

python first-party
expand_more 3 low-confidence finding(s)
low egress production #35089e9c2a1af7bb Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-you/llama_index/llms/you/base.py:25
    response = requests.post(base_url, headers=headers, json=kwargs)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #47530827524577b9 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/llms/llama-index-llms-you/llama_index/llms/you/base.py:35
    response = requests.post(base_url, headers=headers, stream=True, json=params)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #5080657236bccb9a Environment-variable access.
repo/llama-index-integrations/llms/llama-index-llms-you/llama_index/llms/you/base.py:125
        return self.ydc_api_key or os.environ["YDC_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-aimon-rerank

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #d2cb04062d9f799e Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-aimon-rerank/llama_index/postprocessor/aimon_rerank/base.py:41
            api_key = api_key or os.environ["AIMON_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-cohere-rerank

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #0b6cb8e68b359aa9 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-cohere-rerank/llama_index/postprocessor/cohere_rerank/base.py:74
            api_key = api_key or os.environ["COHERE_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-contextual-rerank

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #77b148796000a558 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-contextual-rerank/llama_index/postprocessor/contextual_rerank/base.py:45
            api_key = api_key or os.environ["CONTEXTUAL_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-dashscope-rerank

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #a2be05edb982e9f4 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-dashscope-rerank/llama_index/postprocessor/dashscope_rerank/base.py:35
            api_key = api_key or os.environ["DASHSCOPE_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-ibm

python first-party
expand_more 9 low-confidence finding(s)
low env_fs production #c68993d3dbdb08cb Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:37
        if not (apikey or "WATSONX_APIKEY" in os.environ) and not (

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #fbb4e97092249a9f Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:38
            token or "WATSONX_TOKEN" in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #896a9089dd49b8f0 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:48
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #c9564ea4e6c8e39f Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:59
            and "WATSONX_TOKEN" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #5c864eef9e93c889 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:61
            and "WATSONX_PASSWORD" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #e8d361afd1f1c560 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:63
            and "WATSONX_APIKEY" not in os.environ

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #7f6f30e59eb05c22 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:73
        elif token or "WATSONX_TOKEN" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #1fad753640b3b18e Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:78
        elif password or "WATSONX_PASSWORD" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs production #058236323ab3be28 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-ibm/llama_index/postprocessor/ibm/utils.py:87
        elif apikey or "WATSONX_APIKEY" in os.environ:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-jinaai-rerank

python first-party
expand_more 1 low-confidence finding(s)
low egress production #91ae2ead02a45dbf Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-jinaai-rerank/llama_index/postprocessor/jinaai_rerank/base.py:87
            resp = self._session.post(  # type: ignore
                self.api_url,
                json={
                    "query": query_bundle.query_str,
                    "documents": texts,
                    "model": self.model,
                    "top_n": self.top_n,
                },
            ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-mixedbreadai-rerank

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #97dc847d92480c85 Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-mixedbreadai-rerank/llama_index/postprocessor/mixedbreadai_rerank/base.py:56
            api_key = api_key or os.environ["MXBAI_API_KEY"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-nvidia-rerank

python first-party
expand_more 3 low-confidence finding(s)
low env_fs production #d43f670841861b1c Environment-variable access.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-nvidia-rerank/llama_index/postprocessor/nvidia_rerank/base.py:72
        base_url: Optional[str] = os.getenv("NVIDIA_BASE_URL", BASE_URL),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #0a39150e585e83f0 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-nvidia-rerank/llama_index/postprocessor/nvidia_rerank/base.py:174
        response = client.get(url, headers=_headers)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress production #6423de4858f6230f Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-nvidia-rerank/llama_index/postprocessor/nvidia_rerank/base.py:318
                response = client.post(url, headers=_headers, json=payloads)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-siliconflow-rerank

python first-party
expand_more 1 low-confidence finding(s)
low egress production #95797ca9adad4571 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-siliconflow-rerank/llama_index/postprocessor/siliconflow_rerank/base.py:127
            response = self._session.post(
                self.base_url,
                json={
                    "model": self.model,
                    "query": query_bundle.query_str,
                    "documents": texts,
                    "top_n": self.top_n,
                    **self._model_kwargs,
                },
            ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-tei-rerank

python first-party
expand_more 1 low-confidence finding(s)
low egress production #9a9266ea49cac881 Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/llama-index-integrations/postprocessor/llama-index-postprocessor-tei-rerank/llama_index/postprocessor/tei_rerank/base.py:96
            response = client.post(
                f"{self.base_url}/rerank",
                headers=headers,
                json=json_data,
                timeout=self.timeout,
            )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): llama-index-integrations/storage/kvstore/llama-index-storage-kvstore-dynamodb

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #d67ce0438a3b74b1 Environment-variable access.
repo/llama-index-integrations/storage/kvstore/llama-index-storage-kvstore-dynamodb/llama_index/storage/kvstore/dynamodb/base.py:87
        dynamodb_url = os.getenv("DYNAMODB_URL")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

⚠ Higher-risk dependencies not analyzed

These higher-risk dependencies were not analyzed in this scan — treat the verdict as provisional. This is a scan-coverage limitation, not a detected data leak.

  • httpx http — scan budget exceeded
  • requests http — scan budget exceeded
  • aiohttp http — scan budget exceeded
  • azure-cosmos cloud — scan budget exceeded
  • azure-identity cloud — scan budget exceeded
  • azure-data-tables cloud — scan budget exceeded
  • google-cloud-firestore cloud — scan budget exceeded
  • google-cloud-aiplatform cloud — scan budget exceeded
  • anthropic ai — scan budget exceeded
  • azure-ai-inference cloud — scan budget exceeded
  • cohere ai — scan budget exceeded
  • opentelemetry-sdk analytics — scan budget exceeded
  • opentelemetry-api analytics — scan budget exceeded
  • opentelemetry-semantic-conventions analytics — scan budget exceeded
  • google-cloud-discoveryengine cloud — scan budget exceeded

Skipped dependencies

Production

  • first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-google-rerank prod — scan budget exceeded
  • first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-pinecone-native-rerank prod — scan budget exceeded
  • first-party (python): llama-index-integrations/postprocessor/llama-index-postprocessor-flashrank-rerank prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-alibabacloud-aisearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-docling prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-relational-dashscope prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-slide prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-topic prod — scan budget exceeded
  • first-party (python): llama-index-integrations/node_parser/llama-index-node-parser-chonkie prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-google prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-vectara prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-colbert prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-lancedb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-dashscope prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-postgresml prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-llama-cloud prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-bge-m3 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/indices/llama-index-indices-managed-vertexai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/graph_rag/llama-index-graph-rag-cognee prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-tldw prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-mongodb-atlas-bm25-retriever prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-videodb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-bedrock prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-you prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-vectorize prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-vertexai-search prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-superlinked prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-galaxia prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-duckdb-retriever prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-kendra prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-pathway prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-alletra-x10000 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/retrievers/llama-index-retrievers-bm25 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-honeyhive prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-arize-phoenix prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-langfuse prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-uptrain prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-literalai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-argilla prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-promptlayer prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-wandb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-opik prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-agentops prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-aim prod — scan budget exceeded
  • first-party (python): llama-index-integrations/callbacks/llama-index-callbacks-openinference prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-airweave prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-code-interpreter prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-exa prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-yahoo-finance prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-text-to-image prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-cassandra prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-bing-search prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-google prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-jina prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-igpt-email prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-zapier prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-brightdata prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-python-file prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-database prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-azure-cv prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-moss prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-playgrounds prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-vector-db prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-yelp prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-openapi prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-dappier prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-aws-bedrock-agentcore prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-chatgpt-plugin prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-brave-search prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-azure-translate prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-mcp-discovery prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-salesforce prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-linkup-research prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-artifact-editor prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-openai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-finance prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-multion prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-box prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-tavily-research prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-serpex prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-measurespace prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-seltz prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-jira prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-wikipedia prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-parallel-web-systems prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-requests prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-weather prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-wolfram-alpha prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-waii prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-ionic-shopping prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-arxiv prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-graphql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-neo4j prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-slack prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-shopify prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-valyu prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-cogniswitch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-agentql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-azure-speech prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-signnow prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-typecast prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-vectara-query prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-notion prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-playwright prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-jira-issue prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-mcp prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-desearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-duckduckgo prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-azure-code-interpreter prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-elevenlabs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-metaphor prod — scan budget exceeded
  • first-party (python): llama-index-integrations/tools/llama-index-tools-hive prod — scan budget exceeded
  • first-party (python): llama-index-integrations/evaluation/llama-index-evaluation-tonic-validate prod — scan budget exceeded
  • first-party (python): llama-index-integrations/response_synthesizers/llama-index-response-synthesizers-google prod — scan budget exceeded
  • first-party (python): llama-index-integrations/program/llama-index-program-guidance prod — scan budget exceeded
  • first-party (python): llama-index-integrations/program/llama-index-program-evaporate prod — scan budget exceeded
  • first-party (python): llama-index-integrations/program/llama-index-program-lmformatenforcer prod — scan budget exceeded
  • first-party (python): llama-index-integrations/voice_agents/llama-index-voice-agents-openai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/voice_agents/llama-index-voice-agents-gemini-live prod — scan budget exceeded
  • first-party (python): llama-index-integrations/voice_agents/llama-index-voice-agents-elevenlabs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/extractors/llama-index-extractors-entity prod — scan budget exceeded
  • first-party (python): llama-index-integrations/extractors/llama-index-extractors-relik prod — scan budget exceeded
  • first-party (python): llama-index-integrations/extractors/llama-index-extractors-marvin prod — scan budget exceeded
  • first-party (python): llama-index-integrations/selectors/llama-index-selectors-notdiamond prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-google-genai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-sagemaker-endpoint prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-huggingface prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-isaacus prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-text-embeddings-inference prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-langchain prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-llamafile prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-oci-genai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-bedrock prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-cohere prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-mistralai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-anyscale prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-deepinfra prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-alephalpha prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-textembed prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-ipex-llm prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-vllm prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-alibabacloud-aisearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-huggingface-openvino prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-azure-inference prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-clarifai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-openvino-genai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-openai-like prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-opea prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-azure-openai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-huggingface-optimum prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-vertex-endpoint prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-llm-rails prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-modelscope prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-together prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-siliconflow prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-mixedbreadai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-gaudi prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-upstage prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-dashscope prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-gigachat prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-fastembed prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-cloudflare-workersai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-nomic prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-fireworks prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-nebius prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-databricks prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-ollama prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-nvidia prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-ibm prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-zhipuai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-vertex prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-litellm prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-jinaai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-clip prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-huggingface-optimum-intel prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-voyageai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-instructor prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-adapter prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-premai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-heroku prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-baseten prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-huggingface-api prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-openai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-elasticsearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-yandexgpt prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-oci-data-science prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-autoembeddings prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-netmind prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-xinference prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-oracleai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/embeddings/llama-index-embeddings-premai/llama_index/embeddings/premai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-clickhouse prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-openGauss prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-lindorm prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-pgvecto-rs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-singlestoredb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-alibabacloud-opensearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-jaguar prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-google prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-tair prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-analyticdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-weaviate prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-oracledb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-kdbai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-yugabytedb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-hnswlib prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-s3 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-deeplake prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-oceanbase prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-volcenginemysql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-databricks prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-awsdocdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-mongodb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-tablestore prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-zep prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-redis prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-txtai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-opensearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-cassandra prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-relyt prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-ApertureDB prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-vespa prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-firestore prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-dashvector prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-lantern prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-azurepostgresql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-astra-db prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-neo4jvector prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-gel prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-alibabacloud-mysql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-vectorx prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-tencentvectordb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-baiduvectordb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-couchbase prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-faiss prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-milvus prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-azureaisearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-hologres prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-azurecosmosnosql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-bagel prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-elasticsearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-azurecosmosmongo prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-awadb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-qdrant prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-vertexaivectorsearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-neptune prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-pinecone prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-db2 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-objectbox prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-bigquery prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-moorcheh prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-vearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-supabase prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-duckdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-nile prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-rocksetdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-chroma prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-postgres prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-docarray prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-wordlift prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-tidbvector prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-dynamodb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-lancedb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-solr prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-epsilla prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-typesense prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-timescalevector prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-upstash prod — scan budget exceeded
  • first-party (python): llama-index-integrations/vector_stores/llama-index-vector-stores-mariadb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/agent/llama-index-agent-agentmesh prod — scan budget exceeded
  • first-party (python): llama-index-integrations/agent/llama-index-agent-azure prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-oracleai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-arango-db prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-azstorage-blob prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-singlestore prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-hatena-blog prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-kaltura prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-txtai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-steamship prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-mangadex prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-solr prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-linear prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-smart-pdf-loader prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-minio prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-macrometa-gdn prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-deeplake prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-patentsview prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-bilibili prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-wordpress prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-readwise prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-milvus prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-mangoapps-guides prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-dashvector prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-discord prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-hubspot prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-microsoft-onedrive prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-guru prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-apify prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-alibabacloud-aisearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-trello prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-bagel prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-psychic prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-opendal prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-elasticsearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-feishu-docs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-athena prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-maps prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-google prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-jira prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-iceberg prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-faiss prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-sec-filings prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-docstring-walker prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-database prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-awadb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-astra-db prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-docugami prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-whisper prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-snowflake prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-wikipedia prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-wordlift prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-dashscope prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-microsoft-sharepoint prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-nougat-ocr prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-asana prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-rayyan prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-genius prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-screenpipe prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-toggl prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-boarddocs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-memos prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-cdk prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-notion prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-document360 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-service-now prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-openalex prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-metal prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-confluence prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-string-iterable prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-opensearch prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-obsidian prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-datasets prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-llama-parse prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-microsoft-outlook-emails prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-github prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-box prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-gcs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-chatgpt-plugin prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-youtube-transcript prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-gitbook prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-docling prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-twitter prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-quip prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-mongodb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-stackoverflow prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-typeform prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-azcognitive-search prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-semanticscholar prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-whatsapp prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-myscale prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pdf-marker prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-spotify prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-salesforce prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-assemblyai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-telegram prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-remote-depth prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-oxylabs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-igpt-email prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-stripe-docs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-zyte-serp prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-kibela prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pathway prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-weather prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-zep prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-couchdb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-layoutir prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pandas-ai prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-gitlab prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-huggingface-fs prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-paddle-ocr prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-imdb-review prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-intercom prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-make-com prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-legacy-office prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-slack prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-graphql prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-weaviate prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-file prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-remote prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-firebase-realtimedb prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-feedly-rss prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-mbox prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-jaguar prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-microsoft-outlook prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-zendesk-support prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-web prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-hubspot prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-gong prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-s3 prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-zendesk prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-firestore prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-chroma prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-markitdown prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-json prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-agent-search prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-shopify prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-gpt-repo prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-dad-jokes prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-mondaydotcom prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-reddit prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-hwp prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-structured-data prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-preprocess prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-upstage prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-bitbucket prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-couchbase prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-qdrant prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-earnings-call-transcript prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-joplin prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pebblo prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-zulip prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-graphdb-cypher prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-lilac prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airtable prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-papers prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-pdf-table prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-airbyte-stripe prod — scan budget exceeded
  • first-party (python): llama-index-integrations/readers/llama-index-readers-uniprot prod — scan budget exceeded
  • first-party (python): llama-index-utils/llama-index-utils-azure prod — scan budget exceeded
  • first-party (python): llama-index-utils/llama-index-utils-huggingface prod — scan budget exceeded
  • first-party (python): llama-index-utils/llama-index-utils-qianfan prod — scan budget exceeded
  • first-party (python): llama-index-utils/llama-index-utils-oracleai prod — scan budget exceeded
  • first-party (python): docs/api_reference prod — scan budget exceeded
  • first-party (python): llama-dev/tests/data/llama-index-integrations/storage/subcat/pkg2 prod — scan budget exceeded
  • first-party (python): llama-dev/tests/data/llama-index-integrations/vector_stores/pkg1 prod — scan budget exceeded
  • first-party (python): llama-dev/tests/data/llama-index-packs/pack2 prod — scan budget exceeded
  • first-party (python): llama-dev/tests/data/llama-index-packs/pack1 prod — scan budget exceeded
  • first-party (python): llama-dev/tests/data/llama-index-utils/util prod — scan budget exceeded
  • httpx prod — scan budget exceeded
  • requests prod — scan budget exceeded
  • aiohttp prod — scan budget exceeded
  • azure-cosmos prod — scan budget exceeded
  • azure-identity prod — scan budget exceeded
  • azure-data-tables prod — scan budget exceeded
  • google-cloud-firestore prod — scan budget exceeded
  • google-cloud-aiplatform prod — scan budget exceeded
  • anthropic prod — scan budget exceeded
  • azure-ai-inference prod — scan budget exceeded
  • cohere prod — scan budget exceeded
  • opentelemetry-sdk prod — scan budget exceeded
  • opentelemetry-api prod — scan budget exceeded
  • opentelemetry-semantic-conventions prod — scan budget exceeded
  • google-cloud-discoveryengine prod — scan budget exceeded
  • llama-index-core prod — scan budget exceeded
  • llama-index-embeddings-openai prod — scan budget exceeded
  • llama-index-llms-openai prod — scan budget exceeded
  • nltk prod — scan budget exceeded
  • SQLAlchemy prod — scan budget exceeded
  • dataclasses-json prod — scan budget exceeded
  • deprecated prod — scan budget exceeded
  • fsspec prod — scan budget exceeded
  • nest-asyncio prod — scan budget exceeded
  • numpy prod — scan budget exceeded
  • tenacity prod — scan budget exceeded
  • tiktoken prod — scan budget exceeded
  • typing-extensions prod — scan budget exceeded
  • typing-inspect prod — scan budget exceeded
  • networkx prod — scan budget exceeded
  • dirtyjson prod — scan budget exceeded
  • tqdm prod — scan budget exceeded
  • pillow prod — scan budget exceeded
  • PyYAML prod — scan budget exceeded
  • wrapt prod — scan budget exceeded
  • pydantic prod — scan budget exceeded
  • filetype prod — scan budget exceeded
  • eval-type-backport prod — scan budget exceeded
  • banks prod — scan budget exceeded
  • aiosqlite prod — scan budget exceeded
  • llama-index-workflows prod — scan budget exceeded
  • setuptools prod — scan budget exceeded
  • platformdirs prod — scan budget exceeded
  • tinytag prod — scan budget exceeded
  • click prod — scan budget exceeded
  • packaging prod — scan budget exceeded
  • rich prod — scan budget exceeded
  • nebula3-python prod — scan budget exceeded
  • tidb-vector prod — scan budget exceeded
  • PyMySQL prod — scan budget exceeded
  • falkordb prod — scan budget exceeded
  • neo4j prod — scan budget exceeded
  • aperturedb prod — scan budget exceeded
  • ray prod — scan budget exceeded
  • llama-index-storage-kvstore-dynamodb prod — scan budget exceeded
  • llama-index-storage-kvstore-tablestore prod — scan budget exceeded
  • llama-index-storage-kvstore-mongodb prod — scan budget exceeded
  • llama-index-storage-kvstore-elasticsearch prod — scan budget exceeded
  • llama-index-storage-kvstore-duckdb prod — scan budget exceeded
  • llama-index-kvstore-couchbase prod — scan budget exceeded
  • llama-index-storage-kvstore-azure prod — scan budget exceeded
  • llama-index-storage-kv-store-azurecosmosnosql prod — scan budget exceeded
  • llama-index-storage-kvstore-firestore prod — scan budget exceeded
  • llama-index-storage-kvstore-redis prod — scan budget exceeded
  • llama-index-storage-kvstore-postgres prod — scan budget exceeded
  • llama-index-storage-kvstore-gel prod — scan budget exceeded
  • redis prod — scan budget exceeded
  • llama-index-utils-azure prod — scan budget exceeded
  • upstash_redis prod — scan budget exceeded
  • opensearch-py prod — scan budget exceeded
  • pymongo prod — scan budget exceeded
  • gel prod — scan budget exceeded
  • jinja2 prod — scan budget exceeded
  • psycopg2-yugabytedb prod — scan budget exceeded
  • sqlalchemy-yugabytedb prod — scan budget exceeded
  • aioboto3 prod — scan budget exceeded
  • boto3-stubs prod — scan budget exceeded
  • asyncpg prod — scan budget exceeded
  • psycopg prod — scan budget exceeded
  • tablestore prod — scan budget exceeded
  • duckdb prod — scan budget exceeded
  • llama-index-vector-stores-duckdb prod — scan budget exceeded
  • pyarrow prod — scan budget exceeded
  • elasticsearch prod — scan budget exceeded
  • couchbase prod — scan budget exceeded
  • psycopg2-binary prod — scan budget exceeded
  • ag-ui-protocol prod — scan budget exceeded
  • fastapi prod — scan budget exceeded
  • guidance prod — scan budget exceeded
  • llama-index-program-guidance prod — scan budget exceeded
  • mem0ai prod — scan budget exceeded
  • guardrails-ai prod — scan budget exceeded
  • llama-index-llms-openai-like prod — scan budget exceeded
  • transformers prod — scan budget exceeded
  • modelscope prod — scan budget exceeded
  • torch prod — scan budget exceeded
  • sentencepiece prod — scan budget exceeded
  • ms-swift prod — scan budget exceeded
  • pip prod — scan budget exceeded
  • octoai prod — scan budget exceeded
  • gigachat prod — scan budget exceeded
  • litellm prod — scan budget exceeded
  • mistralai prod — scan budget exceeded
  • pyjwt prod — scan budget exceeded
  • cryptography prod — scan budget exceeded
  • ibm-watsonx-ai prod — scan budget exceeded
  • reka-api prod — scan budget exceeded
  • mlx-lm prod — scan budget exceeded
  • mlx prod — scan budget exceeded
  • llama-index-llms-llama-cpp prod — scan budget exceeded
  • langchain prod — scan budget exceeded
  • llama-index-llms-huggingface prod — scan budget exceeded
  • optimum prod — scan budget exceeded
  • aleph-alpha-client prod — scan budget exceeded
  • ai21 prod — scan budget exceeded
  • llama-index-llms-anthropic prod — scan budget exceeded
  • portkey-ai prod — scan budget exceeded
  • portkey prod — scan budget exceeded
  • openvino-genai prod — scan budget exceeded
  • huggingface-hub prod — scan budget exceeded
  • dashscope prod — scan budget exceeded
  • oci prod — scan budget exceeded
  • google-genai prod — scan budget exceeded
  • premai prod — scan budget exceeded
  • google-generativeai prod — scan budget exceeded
  • sseclient-py prod — scan budget exceeded
  • cleanlab-tlm prod — scan budget exceeded
  • llama-index-utils-qianfan prod — scan budget exceeded
  • llama-cpp-python prod — scan budget exceeded
  • friendli-client prod — scan budget exceeded
  • ipex-llm prod — scan budget exceeded
  • bigdl-core-xe-21 prod — scan budget exceeded
  • bigdl-core-xe-addons-21 prod — scan budget exceeded
  • bigdl-core-xe-batch-21 prod — scan budget exceeded
  • dpcpp-cpp-rt prod — scan budget exceeded
  • intel_extension_for_pytorch prod — scan budget exceeded
  • mkl-dpcpp prod — scan budget exceeded
  • onednn prod — scan budget exceeded
  • torchvision prod — scan budget exceeded
  • clarifai prod — scan budget exceeded
  • contextual-client prod — scan budget exceeded
  • python-dotenv prod — scan budget exceeded
  • ollama prod — scan budget exceeded
  • tokenizers prod — scan budget exceeded
  • llama-index-readers-upstage prod — scan budget exceeded
  • alibabacloud-searchplat20240529 prod — scan budget exceeded
  • tritonclient prod — scan budget exceeded
  • konko prod — scan budget exceeded
  • zhipuai prod — scan budget exceeded
  • sniffio prod — scan budget exceeded
  • termcolor prod — scan budget exceeded
  • llama-index-instrumentation prod — scan budget exceeded
  • fastembed prod — scan budget exceeded
  • voyageai prod — scan budget exceeded
  • llmlingua prod — scan budget exceeded
  • aimon prod — scan budget exceeded
  • colpali-engine prod — scan budget exceeded
  • presidio-analyzer prod — scan budget exceeded
  • presidio-anonymizer prod — scan budget exceeded
  • rank-llm prod — scan budget exceeded
  • mixedbread prod — scan budget exceeded
  • pinecone prod — scan budget exceeded
  • flashrank prod — scan budget exceeded
  • docling-core prod — scan budget exceeded
  • chonkie prod — scan budget exceeded
  • llama-index-vector-stores-google prod — scan budget exceeded
  • llama-index-response-synthesizers-google prod — scan budget exceeded
  • lancedb prod — scan budget exceeded
  • pylance prod — scan budget exceeded
  • tantivy prod — scan budget exceeded
  • polars prod — scan budget exceeded
  • open-clip-torch prod — scan budget exceeded
  • llama-index-embeddings-dashscope prod — scan budget exceeded
  • llama-index-readers-dashscope prod — scan budget exceeded
  • llama-index-node-parser-dashscope prod — scan budget exceeded
  • pgml prod — scan budget exceeded
  • peft prod — scan budget exceeded
  • flagembedding prod — scan budget exceeded
  • cognee prod — scan budget exceeded
  • graphistry prod — scan budget exceeded
  • videodb prod — scan budget exceeded
  • vectorize-client prod — scan budget exceeded
  • google-auth-httplib2 prod — scan budget exceeded
  • google-auth-oauthlib prod — scan budget exceeded
  • superlinked prod — scan budget exceeded
  • pydi-client prod — scan budget exceeded
  • bm25s prod — scan budget exceeded
  • pystemmer prod — scan budget exceeded
  • honeyhive prod — scan budget exceeded
  • openinference-instrumentation-llama-index prod — scan budget exceeded
  • langfuse prod — scan budget exceeded
  • uptrain prod — scan budget exceeded
  • argilla prod — scan budget exceeded
  • argilla-llama-index prod — scan budget exceeded
  • promptlayer prod — scan budget exceeded
  • wandb prod — scan budget exceeded
  • agentops prod — scan budget exceeded
  • aim prod — scan budget exceeded
  • jwt prod — scan budget exceeded
  • airweave-sdk prod — scan budget exceeded