Close Open Privacy Scan
App Privacy Score
Low risk · 219 finding(s)
Dependency score: 22 (High risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Application data flows
No application data flows were found. See dependency data flows below.
hub Dependency data flows (91)
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:16pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:36pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:41pkgs/npm/[email protected]__reposrc/examples/chat_completion.ts:6 → pkgs/npm/[email protected]__reposrc/examples/chat_completion.ts:26pkgs/npm/[email protected]__reposrc/examples/get_contents_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/get_contents_example.ts:15pkgs/npm/[email protected]__reposrc/examples/links_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/links_example.ts:14pkgs/npm/[email protected]__reposrc/examples/links_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/links_example.ts:21pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:12pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:19pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:32pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:33pkgs/npm/[email protected]__reposrc/examples/openai_responses.ts:6 → pkgs/npm/[email protected]__reposrc/examples/openai_responses.ts:17pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:17pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:24pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:30pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:31pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:37pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:43pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:44pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:62pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:63pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 → pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:67pkgs/npm/[email protected]__reposrc/examples/research_task_bulk_example.ts:5 → pkgs/npm/[email protected]__reposrc/examples/research_task_bulk_example.ts:77pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:5 → pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:34pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:5 → pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:38pkgs/npm/[email protected]__reposrc/examples/search_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/search_example.ts:11pkgs/npm/[email protected]__reposrc/examples/search_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/search_example.ts:18pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:3 → pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:11pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:3 → pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:21pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:16pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:3 → pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:19pkgs/npm/[email protected]__reposrc/examples/subpages.ts:3 → pkgs/npm/[email protected]__reposrc/examples/subpages.ts:19pkgs/npm/[email protected]__reposrc/examples/subpages.ts:3 → pkgs/npm/[email protected]__reposrc/examples/subpages.ts:30pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 → pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:35pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 → pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:41pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 → pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:65pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 → pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:71pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 → pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:78pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 → pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:49pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 → pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:50pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 → pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:68pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:56pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:70pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:76pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:106pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:107pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:108pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:111pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:114pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:118pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:122pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:123pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:125pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:137pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 → pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:146pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:63pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:64pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:74pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:78pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:80pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:91pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:103pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:107pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:118pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:120pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:128pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:135pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:140pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 → pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:143pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:101pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:103pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:105pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:116pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:117pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:121pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:123pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:145pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:147pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:150pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:171pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:193pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:196pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:200pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:216pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:218pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:240pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:248pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:112pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:166pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:213pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 → pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:259</> First-Party Code
first-party (npm)
npm first-partyexpand_more 24 low-confidence finding(s)
process.env.AGNOST_LOG_LEVEL = 'error';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const redisUrl = process.env.KV_REST_API_URL || process.env.UPSTASH_REDIS_REST_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const redisToken = process.env.KV_REST_API_TOKEN || process.env.UPSTASH_REDIS_REST_TOKEN;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const qpsLimit = parseInt(process.env.RATE_LIMIT_QPS || '2', 10);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const dailyLimit = parseInt(process.env.RATE_LIMIT_DAILY || '50', 10);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let exaApiKey = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let debug = process.env.DEBUG === 'true';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if (!enabledTools && process.env.ENABLED_TOOLS) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
process.env.ENABLED_TOOLS
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if (!defaultSearchType && process.env.DEFAULT_SEARCH_TYPE) {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const dst = process.env.DEFAULT_SEARCH_TYPE;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
mcpMaxDurationSeconds: parsePositiveInteger(process.env.MCP_MAX_DURATION_SECONDS),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
agentCallWindowMs: parsePositiveInteger(process.env.AGENT_CALL_WINDOW_MS),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const debug = process.env.DEBUG === 'true';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const bypassPrefix = process.env.RATE_LIMIT_BYPASS;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const bypassApiKey = process.env.EXA_API_KEY_BYPASS;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const oauthUserAgents = process.env.OAUTH_USER_AGENTS?.split(',').map(s => s.trim()).filter(Boolean) || [];
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const OAUTH_ISSUER = process.env.OAUTH_ISSUER || 'https://auth.exa.ai';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const raw = process.env.OPENAI_APPS_CHALLENGE_TOKEN || '';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
process.env.AGNOST_LOG_LEVEL = process.env.AGNOST_LOG_LEVEL ?? "error";
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return new Exa(typeof exaApiKey === 'string' && exaApiKey.length > 0 ? exaApiKey : process.env.EXA_API_KEY || '');
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
cached ??= stripFrontmatter(readFileSync(findSkillFile(), "utf8"));
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const OAUTH_ISSUER = process.env.OAUTH_ISSUER || 'https://auth.exa.ai';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const OAUTH_AUDIENCE = process.env.OAUTH_AUDIENCE || 'https://mcp.exa.ai';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
exa-js
npm dependency console.log("Answer result:", JSON.stringify(answer, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Answer result:", JSON.stringify(structuredAnswer, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Answer result:", JSON.stringify(answerFromLocation, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chunk);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results:", contentsResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results with links:", JSON.stringify(search, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results with links:", JSON.stringify(contents, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results without livecrawl:", JSON.stringify(contentsWithoutLivecrawl, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results with livecrawl:", JSON.stringify(contentsWithLivecrawl, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Length of text without livecrawl:", textWithoutLivecrawl.length);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Length of text with livecrawl:", textWithLivecrawl.length);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chunk);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Created research: ${research.researchId}\n`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Status: ${withoutEvents.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Has events array: ${Array.isArray(withoutEvents.events)}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Events count: ${withoutEvents.events?.length ?? 0}\n`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Status: ${withEvents.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Has events array: ${Array.isArray(withEvents.events)}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Events count: ${withEvents.events?.length ?? 0}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Final status: ${finalState.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Total events: ${finalState.events?.length ?? 0}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(finalState.output.content.substring(0, 200) + "...");
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Event:", JSON.stringify(event, undefined, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Created Research ID:", research.researchId);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Research Event:", event);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results:", searchResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results with contents:", searchWithContentsResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results:",
searchResponse.results.map((it) => it)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results with contents:",
searchWithContentsResponse.results
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nChunk:", chunk.content); // Write partial text as it arrives
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nCitations:", chunk.citations); // Handle citations when they arrive
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results with subpages:",
JSON.stringify(search, null, 2)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Get contents results with subpages:",
JSON.stringify(contents, null, 2)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created known companies webset: ${knownCompaniesWebset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nKnown companies (${knownItems.data.length} found):`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created new webset: ${newWebset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nNew companies found (${newItems.data.length} total):`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`\n✓ Successfully excluded ${knownItems.data.length} known companies from search`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` ID: ${createdImport.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status: ${createdImport.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Records processed: ${completedImport.count}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created webset: https://websets.exa.ai/${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Webset found ${itemsResponse.data.length} items`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - ${item.properties.description}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created monitor: ${monitor.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status: ${monitor.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Next run: ${monitor.nextRunAt || "Not scheduled"}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nMonitors for webset ${webset.id}:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - ${m.id}: ${m.behavior.type} monitor (${m.status})`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nMonitor runs for ${monitor.id}:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Run ${run.id}: ${run.status} (${run.type})`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Created: ${run.createdAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Completed: ${run.completedAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Monitor status updated to: ${updatedMonitor.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`- View your webset at: https://websets.exa.ai/${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webset created with ID: ${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Status: ${webset.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webset processing complete. Status: ${idleWebset.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${items.data.length} items:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`- ${
item.properties.type === "company"
? item.properties.company.name
: "Unknown"
}: ${item.properties.url}`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Retrieved ${allItems.length} items in total`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Enrichment created with ID: ${enrichment.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Expanded Webset has ${expandedWebset.items?.length ?? 0} items`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${events.data.length} recent events:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`- ${event.type} at ${event.createdAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webhook created with ID: ${webhook.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${attempts.data.length} webhook attempts`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`- ${attempt.eventType} at ${attempt.attemptedAt} (${attempt.successful ? "success" : "failed"})`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status code: ${attempt.responseStatusCode}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Title:", comparison.title);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(comparison.executive_summary);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nItems Compared:", comparison.items_compared.join(", "));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nRecommended Choice: ${comparison.winner}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Reasoning: ${comparison.reasoning}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(comparison.recommendation);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Topic:", explanation.topic);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(explanation.simple_explanation);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(explanation.technical_details);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Market:", research.market_name);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Market Size:", research.market_size);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Growth Rate:", research.growth_rate);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(research.outlook);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Summary:", comparison.summary);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 37 low-confidence finding(s)
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
apiKey: process.env.EXA_API_KEY,
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY!);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY!);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
apiKey: process.env.EXA_API_KEY,
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const apiKey = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const apiKey = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const apiKey = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const exa = new Exa(process.env.EXA_API_KEY);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_API_KEY = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const EXA_BASE_URL = process.env.EXA_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
import * as fs from "fs";
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
this.config = JSON.parse(fs.readFileSync(configPath, "utf-8"));
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return this.client.request<T>(
`/agent/runs${endpoint}`,
method,
data,
params,
headers
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
apiKey = process.env.EXA_API_KEY;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return this.client.request<T>(
`/monitors${endpoint}`,
method,
data,
params
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
return this.client.request<T>(
`/research/v1${endpoint}`,
method,
data,
params
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
return this.client.request<T>(
`/websets${endpoint}`,
method,
data,
params,
headers
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const uploadResponse = await fetch(importResponse.uploadUrl, {
method: "PUT",
body: csvBuffer as BodyInit,
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
@modelcontextprotocol/sdk
npm dependencyexpand_more 38 low-confidence finding(s)
await client.request({ method: 'resources/list' }, ListResourcesResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const response = await fetch(url);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const response = await fetch(url);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
writeFileSync(outputPath, fullContent, 'utf-8');
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const value = process.env[key];
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const toolsResult = await client.request(toolsRequest, ListToolsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(request, CallToolResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(toolRequest, CallToolResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const toolsResult = await client.request(toolsRequest, ListToolsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
return client
.request(request, CallToolResultSchema)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const DEFAULT_SERVER_URL = process.env.MCP_SERVER_URL || 'http://localhost:3000/mcp';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const clientId = process.env.MCP_CLIENT_ID;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const privateKeyPem = process.env.MCP_CLIENT_PRIVATE_KEY_PEM;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const algorithm = process.env.MCP_CLIENT_ALGORITHM || 'RS256';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const clientSecret = process.env.MCP_CLIENT_SECRET;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const result = await this.client.request(request, ListToolsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await this.client.request(request, CallToolResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const resourcesResult = await client.request(
{
method: 'resources/list',
params: {}
},
ListResourcesResultSchema
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const toolsResult = await client.request(toolsRequest, ListToolsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(request, CallToolResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(request, CallToolResultSchema, {
resumptionToken: notificationsToolLastEventId,
onresumptiontoken: onLastEventIdUpdate
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const promptsResult = await client.request(promptsRequest, ListPromptsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const promptResult = await client.request(promptRequest, GetPromptResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const resourcesResult = await client.request(resourcesRequest, ListResourcesResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(request, ReadResourceResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(
{
method: 'tools/call',
params: {
name: 'long-task',
arguments: {}
}
},
CallToolResultSchema,
{
// Track resumption tokens for debugging
onresumptiontoken: token => {
lastEventId = token;
console.log(`[Event ID] ${token}`);
}
}
);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const toolsResult = await client.request(toolsRequest, ListToolsResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const result = await client.request(request, CallToolResultSchema);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const PORT = process.env.PORT ? parseInt(process.env.PORT, 10) : 3000;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const MCP_PORT = process.env.MCP_PORT ? parseInt(process.env.MCP_PORT, 10) : 3000;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const AUTH_PORT = process.env.MCP_AUTH_PORT ? parseInt(process.env.MCP_AUTH_PORT, 10) : 3001;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const response = await fetch(endpoint, {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
token: token
}).toString()
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const PORT = process.env.MCP_PORT ? parseInt(process.env.MCP_PORT, 10) : 3000;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const MCP_PORT = process.env.MCP_PORT ? parseInt(process.env.MCP_PORT, 10) : 3000;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const AUTH_PORT = process.env.MCP_AUTH_PORT ? parseInt(process.env.MCP_AUTH_PORT, 10) : 3001;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const response = await fetch(endpoint, {
method: 'POST',
headers: {
'Content-Type': 'application/x-www-form-urlencoded'
},
body: new URLSearchParams({
token: token
}).toString()
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const PORT = process.env.PORT ? parseInt(process.env.PORT, 10) : 8000;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
process.env.MCP_DANGEROUSLY_ALLOW_INSECURE_ISSUER_URL === 'true' || process.env.MCP_DANGEROUSLY_ALLOW_INSECURE_ISSUER_URL === '1';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
jose
npm dependencyexpand_more 23 low-confidence finding(s)
const script = readFileSync('./tap/run-browser.js', 'utf-8')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const response = await fetch(jwksUri).then((r) => r.json())
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const jwks = lib.createRemoteJWKSet(new URL(jwksUri))
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const { readFileSync, writeFileSync } = require('fs')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
let code = readFileSync(file, 'utf8')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(file, result)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const { readFileSync, writeFileSync, globSync } = require('fs')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const readme = readFileSync('docs/README.md')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const content = readFileSync(file, 'utf-8')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(file, updatedContent, 'utf-8')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync('docs/README.md', readme)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(
'dist/deno/README.md',
readFileSync('docs/readme.md', { encoding: 'utf-8' })
.replace(/^`jose` is distributed.+$\n\n/m, '')
.replace(
/\*\*[\s\S]+```/gm,
`**\`example\`** Deno import
\`\`\`js
import * as jose from 'https://deno.land/x/jose@${tagName}/index.ts'
\`\`\``,
)
.replace(/(\]\()(?!https)/gm, `](https://github.com/panva/jose/blob/${tagName}/docs/`),
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
readFileSync('docs/readme.md', { encoding: 'utf-8' })
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(path, readFileSync(path, { encoding: 'utf-8' }).replace(regex, replacement))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(file, trimExcessComment(filterExamples(readFileSync(file, { encoding: 'utf-8' }))))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const { readFileSync, writeFileSync } = require('fs')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync(path, readFileSync(path, { encoding: 'utf-8' }).replace(/v(\d+\.\d+\.\d+)/g, tagName))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const { readFileSync, writeFileSync, unlinkSync } = require('fs')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const pkg = JSON.parse(readFileSync('./package.json'))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
writeFileSync('./package.json', `${JSON.stringify(pkg, null, 2)}\n`)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const fs = require('fs')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs.writeFileSync(
'notes.md',
fs
.readFileSync('CHANGELOG.diff')
.toString()
.split('\n')
.filter((line) => line.startsWith('+') && !line.startsWith('+++'))
.map((line) => line.slice(1))
.slice(3)
.join('\n'),
)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs
.readFileSync('CHANGELOG.diff')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
mcp-handler
npm dependencyexpand_more 5 low-confidence finding(s)
redisUrl: process.env.REDIS_URL,
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
redisUrl: process.env.REDIS_URL,
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
await fs.readFile(path.join(process.cwd(), "package.json"), "utf-8")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
await fs.writeFile(routeFilePath, ROUTE_TEMPLATE);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
redisUrl: process.env.REDIS_URL || process.env.KV_URL,
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
whoami
npm dependencyexpand_more 1 low-confidence finding(s)
var result = name ? name : process.env.USER;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
Skipped dependencies
Production
- agnost prod — dist-only: no readable source