Close Open Privacy Scan

bolt Snapshot: commit 054fe26
science engine v1.23
schedule 2026-07-25T07:15:54.298527+00:00

verified_user Application data leak confirmed

High-confidence data exfiltration identified in application code.

smart_toy MCP server detected: @anthropic-ai/sdk, @modelcontextprotocol/sdk, openai — detected in dependencies, not a safety judgment.
Incomplete scan — only 0/200 dependencies were analyzed. Treat the score as provisional.

App Privacy Score

0 /100
High privacy risk — application leak confirmed

High risk · 2764 finding(s)

Based on: 97 first-party package(s) · 0/200 deps analyzed

Dependency score: 100 (Low risk)

bar_chart Score Breakdown

pii_flow −60
telemetry −25
egress −15
env_fs −3

list Scan Summary

3 high 77 medium 2684 low
First-party packages: 39
Dependency packages: 0
Ecosystem: npm

swap_horiz Confirmed data exfiltration in application code

External domains: 302.aia.comagent-gateway.lobehub.comai-gateway.vercel.shai-userxxxxxxxxxx.services.ai.azure.comai.360.cnai.360.comai.azure.comai.gitee.comai.google.devai.meta.comaihubmix.comalipaytbox.yuque.comampcode.comanalytics.umami.isanthropic.comapi-data.line.meapi-inference.modelscope.cnapi.302.aiapi.360.cnapi.abc.comapi.ai21.comapi.anthropic.comapi.baichuan-ai.comapi.bfl.aiapi.bochaai.comapi.cerebras.aiapi.cloudflare.comapi.cohere.aiapi.cohere.comapi.cometapi.comapi.deepseek.comapi.exa.aiapi.firecrawl.devapi.fireworks.aiapi.github.comapi.githubcopilot.comapi.groq.comapi.kimi.comapi.line.meapi.lingyiwanwu.comapi.lkeap.cloud.tencent.comapi.longcat.chatapi.minimax.ioapi.minimaxi.comapi.mistral.aiapi.moonshot.cnapi.novita.aiapi.openai.comapi.perplexity.aiapi.ppinfra.comapi.replicate.comapi.sambanova.aiapi.search.brave.comapi.search1api.comapi.sgroup.qq.comapi.siliconflow.cnapi.slack.comapi.stepfun.comapi.straico.comapi.studio.nebius.comapi.tavily.comapi.tbox.cnapi.telegram.orgapi.together.xyzapi.upstage.aiapi.v0.devapi.x.aiapi.xiaomimimo.comapig.console.aliyun.comapp.lobehub.comapp.posthog.comark.cn-beijing.volces.comarxiv.orgauth.openai.comauth.x.aiazure.microsoft.combfl.aibluebubbles.appbots.qq.combuild.nvidia.comcdn.jsdelivr.netcdn.tailwindcss.comcerebras.aichat-plugins.lobehub.comchat-preview.lobehub.comchat.intern-ai.org.cnchatapi.akash.networkchatgpt.comchrome.browserless.ioclaude.aicloud.baidu.comcloud.google.comcloud.infini-ai.comcloud.langfuse.comcloud.sambanova.aicloud.tencent.comcloud.zidongtaichu.comcoding.dashscope.aliyuncs.comcohere.comcometapi.comcomposio.devconsole.bce.baidu.comconsole.cloud.google.comconsole.cloud.tencent.comconsole.groq.comcvpr.thecvf.comdashscope.aliyuncs.comdatatracker.ietf.orgdeepsearch.jina.aideepseek.comdeveloper.mozilla.orgdeveloper.qiniu.comdevelopers.cloudflare.comdevelopers.line.bizdevelopers.upstage.aidevice-gateway.lobehub.comdiscord.comdiscord.ggdocs.ai21.comdocs.aihubmix.comdocs.anthropic.comdocs.aws.amazon.comdocs.cohere.comdocs.mistral.aidocs.perplexity.aidocs.together.aidocs.vllm.aidocs.x.aidocs.z.aifal.aifireworks.aigenerativelanguage.googleapis.comgithub.comgroq.comhelp.aliyun.comhigress.cnhub-apac-1.lobeobjects.spacehuggingface.cohunyuan.tencent.comicons.duckduckgo.comilinkai.weixin.qq.cominference-docs.cerebras.aiinference.readthedocs.iointegrate.api.nvidia.cominternlm.intern-ai.org.cnjina.aikagi.comlearn.chatgpt.comlearn.microsoft.comling.tbox.cnlmstudio.ailobe.lilobechat.comlobehub.comlocal.filelongcat.chatmarket.lobehub.commedium.commistral.aimodels.devmodels.github.aimodelscope.cnnebius.comnovac2c.cdn.weixin.qq.comnovita.ainpmmirror.comollama.comopen.bigmodel.cnopen.feishu.cnopen.larksuite.comopenai.comopenai.qiniu.comopencode.aiopenrouter.aiplatform.baichuan-ai.complatform.deepseek.complatform.lingyiwanwu.complatform.minimax.ioplatform.minimaxi.complatform.moonshot.aiplatform.openai.complatform.sensenova.cnplatform.stepfun.complatform.xiaomimimo.complausible.ioplay.google.complugin.anspire.cnppinfra.comq.qq.comqianfan.baidubce.comqstash.upstash.ior.jina.air.jinaai.cnraw.githubusercontent.comregistry.npmjs.orgregistry.npmmirror.comreplicate.comrouter.huggingface.cos.jina.ais.jinaai.cnsandbox.api.sgroup.qq.comscribe.ripsiliconflow.cnslack.comsogou.comspark-api-open.xf-yun.comstepfun.comstraico.comstudio.ai21.comstudio.nebius.comt.metestflight.apple.comtoken.sensenova.cntokenhub.tencentmaas.comupstage.aiv0.devvercel.comwallstreetcn.comwanqing.streamlakeapi.comworkflow-run-guard.localwww.aliyun.comwww.bing.comwww.comfy.orgwww.google.comwww.googleapis.comwww.lingyiwanwu.comwww.minimaxi.comwww.moonshot.aiwww.perplexity.aiwww.qiniu.comwww.qiumiwu.comwww.reddit.comwww.search1api.comwww.sensenova.cnwww.streamlake.comwww.together.aiwww.volcengine.comwww.w3.orgwww.xfyun.cnwww.youtube.comx.aix.comxinghuo.xfyun.cnyour-proxy-url.comyour-resource.cognitiveservices.azure.comyour-server.comyour.new-api-provider.comz.aizenmux.aizhipuai.cnzhuanlan.zhihu.com

high first-party (npm) A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:120
  2. 2sinkrepo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:148
high first-party (npm): packages/model-runtime A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/packages/model-runtime/src/providers/azureai/index.ts:33
  2. 2sinkrepo/packages/model-runtime/src/providers/azureai/index.ts:67
high first-party (npm): packages/model-runtime A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/packages/model-runtime/src/providers/comfyui/index.ts:96
  2. 2sinkrepo/packages/model-runtime/src/providers/comfyui/index.ts:101
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/routers/async/caller.ts:23
  2. 2sinkrepo/apps/server/src/routers/async/caller.ts:29
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:48
  2. 2sinkrepo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:47
medium first-party (npm) Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/bot/BotMessageRouter.ts:780
  2. 2sinkrepo/apps/server/src/services/bot/BotMessageRouter.ts:798
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/desktopRelease/index.ts:120
  2. 2sinkrepo/apps/server/src/services/desktopRelease/index.ts:123
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/anspire/index.ts:74
  2. 2sinkrepo/apps/server/src/services/search/impls/anspire/index.ts:72
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/bocha/index.ts:64
  2. 2sinkrepo/apps/server/src/services/search/impls/bocha/index.ts:63
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/brave/index.ts:70
  2. 2sinkrepo/apps/server/src/services/search/impls/brave/index.ts:67
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/exa/index.ts:69
  2. 2sinkrepo/apps/server/src/services/search/impls/exa/index.ts:67
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/firecrawl/index.ts:69
  2. 2sinkrepo/apps/server/src/services/search/impls/firecrawl/index.ts:68
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/jina/index.ts:48
  2. 2sinkrepo/apps/server/src/services/search/impls/jina/index.ts:46
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/kagi/index.ts:52
  2. 2sinkrepo/apps/server/src/services/search/impls/kagi/index.ts:51
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/search1api/index.ts:85
  2. 2sinkrepo/apps/server/src/services/search/impls/search1api/index.ts:84
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/services/search/impls/tavily/index.ts:63
  2. 2sinkrepo/apps/server/src/services/search/impls/tavily/index.ts:62
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/apps/server/src/workflows/runGuard/qstashCancel.ts:79
  2. 2sinkrepo/apps/server/src/workflows/runGuard/qstashCancel.ts:95
medium first-party (npm) A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:43
  2. 2sinkrepo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:64
medium first-party (npm): packages/web-crawler A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/web-crawler/src/crawImpl/exa.ts:25
  2. 2sinkrepo/packages/web-crawler/src/crawImpl/exa.ts:38
medium first-party (npm): packages/web-crawler A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/web-crawler/src/crawImpl/firecrawl.ts:54
  2. 2sinkrepo/packages/web-crawler/src/crawImpl/firecrawl.ts:67
medium first-party (npm): packages/web-crawler A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/web-crawler/src/crawImpl/jina.ts:11
  2. 2sinkrepo/packages/web-crawler/src/crawImpl/jina.ts:18
medium first-party (npm): packages/web-crawler A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/web-crawler/src/crawImpl/search1api.ts:19
  2. 2sinkrepo/packages/web-crawler/src/crawImpl/search1api.ts:30
medium first-party (npm): packages/web-crawler A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/web-crawler/src/crawImpl/tavily.ts:26
  2. 2sinkrepo/packages/web-crawler/src/crawImpl/tavily.ts:39
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:51
  2. 2sinkrepo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:50
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:167
  2. 2sinkrepo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:166
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/aihubmix/index.ts:163
  2. 2sinkrepo/packages/model-runtime/src/providers/aihubmix/index.ts:182
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/bfl/createImage.ts:125
  2. 2sinkrepo/packages/model-runtime/src/providers/bfl/createImage.ts:123
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/bfl/createImage.ts:161
  2. 2sinkrepo/packages/model-runtime/src/providers/bfl/createImage.ts:159
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/cloudflare/index.ts:77
  2. 2sinkrepo/packages/model-runtime/src/providers/cloudflare/index.ts:95
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/cloudflare/index.ts:77
  2. 2sinkrepo/packages/model-runtime/src/providers/cloudflare/index.ts:157
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/comfyui/index.ts:96
  2. 2sinkrepo/packages/model-runtime/src/providers/comfyui/index.ts:107
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/google/index.ts:136
  2. 2sinkrepo/packages/model-runtime/src/providers/google/index.ts:490
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/minimax/createVideo.ts:55
  2. 2sinkrepo/packages/model-runtime/src/providers/minimax/createVideo.ts:54
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/minimax/createVideo.ts:78
  2. 2sinkrepo/packages/model-runtime/src/providers/minimax/createVideo.ts:77
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/minimax/createVideo.ts:177
  2. 2sinkrepo/packages/model-runtime/src/providers/minimax/createVideo.ts:176
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/nebius/index.ts:34
  2. 2sinkrepo/packages/model-runtime/src/providers/nebius/index.ts:32
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:41
  2. 2sinkrepo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:40
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:126
  2. 2sinkrepo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:125
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/straico/index.ts:46
  2. 2sinkrepo/packages/model-runtime/src/providers/straico/index.ts:45
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:78
  2. 2sinkrepo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:77
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/wenxin/createVideo.ts:37
  2. 2sinkrepo/packages/model-runtime/src/providers/wenxin/createVideo.ts:36
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/wenxin/createVideo.ts:137
  2. 2sinkrepo/packages/model-runtime/src/providers/wenxin/createVideo.ts:136
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/xai/createVideo.ts:35
  2. 2sinkrepo/packages/model-runtime/src/providers/xai/createVideo.ts:34
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/xai/createVideo.ts:127
  2. 2sinkrepo/packages/model-runtime/src/providers/xai/createVideo.ts:126
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/zhipu/createImage.ts:39
  2. 2sinkrepo/packages/model-runtime/src/providers/zhipu/createImage.ts:38
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/zhipu/createImage.ts:134
  2. 2sinkrepo/packages/model-runtime/src/providers/zhipu/createImage.ts:133
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/zhipu/createVideo.ts:41
  2. 2sinkrepo/packages/model-runtime/src/providers/zhipu/createVideo.ts:40
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/zhipu/createVideo.ts:147
  2. 2sinkrepo/packages/model-runtime/src/providers/zhipu/createVideo.ts:146
medium first-party (npm): packages/model-runtime A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcerepo/packages/model-runtime/src/providers/zhipu/index.ts:222
  2. 2sinkrepo/packages/model-runtime/src/providers/zhipu/index.ts:221

</> First-Party Code

first-party (npm)

npm first-party
high pii_flow production #cca4c2ca14da2118 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:148 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:120 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:148
      body: new URLSearchParams({
        client_id: config.clientId,
        code: authorization.authorization_code,
        code_verifier: authorization.code_verifier,
        grant_type: 'authorization_code',
        redirect_uri: `${issuer}/deviceauth/callback`,
      }).toString(),

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium pii_flow production #169c5e03c225e041 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/routers/async/caller.ts:29 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/routers/async/caller.ts:23 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/routers/async/caller.ts:29
        headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #728fcf05e78f1fb6 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:47 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:48 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:47
        headers: {
          ...(process.env.VERCEL_AUTOMATION_BYPASS_SECRET && {
            'x-vercel-protection-bypass': process.env.VERCEL_AUTOMATION_BYPASS_SECRET,
          }),
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #1f6b4edd215f148c Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
repo/apps/server/src/services/bot/BotMessageRouter.ts:798 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/bot/BotMessageRouter.ts:780 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/bot/BotMessageRouter.ts:798
        await thread.post(text);

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #272321559bc1cdb0 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/desktopRelease/index.ts:123 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/desktopRelease/index.ts:120 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/desktopRelease/index.ts:123
    headers: {
      ...(token ? { Authorization: `Bearer ${token}` } : {}),
      'Accept': 'application/vnd.github+json',
      'User-Agent': 'lobehub-server',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #a622a6f6720bb583 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/anspire/index.ts:72 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/anspire/index.ts:74 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/anspire/index.ts:72
        headers: {
          'Accept': '*/*',
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Connection': 'keep-alive ',
          'Content-Type': 'application/json',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #825ab03d80fb4af1 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/bocha/index.ts:63 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/bocha/index.ts:64 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/bocha/index.ts:63
        headers: {
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Content-Type': 'application/json',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #fa7698e5058036b0 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/brave/index.ts:67 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/brave/index.ts:70 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/brave/index.ts:67
        headers: {
          'Accept': 'application/json',
          'Accept-Encoding': 'gzip',
          'X-Subscription-Token': this.apiKey ? this.apiKey : '',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #72918dd9165e7544 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/exa/index.ts:67 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/exa/index.ts:69 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/exa/index.ts:67
        headers: {
          'Content-Type': 'application/json',
          'x-api-key': this.apiKey ? this.apiKey : '',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #0662734104ebe9fa A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/firecrawl/index.ts:68 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/firecrawl/index.ts:69 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/firecrawl/index.ts:68
        headers: {
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Content-Type': 'application/json',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #ac008dfc8c1a4e95 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/jina/index.ts:46 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/jina/index.ts:48 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/jina/index.ts:46
        headers: {
          'Accept': 'application/json',
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Content-Type': 'application/json',
          'X-Respond-With': 'no-content',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #d28b64308e80049b A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/kagi/index.ts:51 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/kagi/index.ts:52 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/kagi/index.ts:51
        headers: {
          Authorization: this.apiKey ? `Bot ${this.apiKey}` : '',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #15be6fd952469e31 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/search1api/index.ts:84 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/search1api/index.ts:85 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/search1api/index.ts:84
        headers: {
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Content-Type': 'application/json',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #0f4a92ea7a2401a8 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/services/search/impls/tavily/index.ts:62 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/tavily/index.ts:63 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/services/search/impls/tavily/index.ts:62
        headers: {
          'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
          'Content-Type': 'application/json',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium telemetry production #d0815e49c503d0b5 capability detected · no path traced Structural telemetry/analytics emit (event capture or batched event insert). Confirm user consent and what payload is sent to the destination.
repo/apps/server/src/services/user/index.ts:38
    analytics?.identify(user.id, {
      email: user.email ?? undefined,
      firstName: user.firstName ?? undefined,
      lastName: user.lastName ?? undefined,
      phone: user.phone ?? undefined,
      username: user.username ?? undefined,
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #14e851154270d30d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/apps/server/src/services/user/index.ts:45
    analytics?.track({
      name: 'user_register_completed',
      properties: {
        spm: 'user_service.init_user.user_created',
      },
      userId: user.id,
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow production #289c1a499e45f738 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/apps/server/src/workflows/runGuard/qstashCancel.ts:95 · flow /tmp/closeopen-u_dp06n_/repo/apps/server/src/workflows/runGuard/qstashCancel.ts:79 → /tmp/closeopen-u_dp06n_/repo/apps/server/src/workflows/runGuard/qstashCancel.ts:95
    headers: {
      'Authorization': `Bearer ${token}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #7451e0168e245681 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:64 · flow /tmp/closeopen-u_dp06n_/repo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:43 → /tmp/closeopen-u_dp06n_/repo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:64
      return ssrfSafeFetch(pricingUrl, { headers: currentHeaders });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium telemetry production #1cf0862ad7025850 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/components/Analytics/HomePageTracker.tsx:15
      analytics.track({
        name: 'main_page_view',
        properties: {
          spm: 'homepage.main_page.view',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #2c4eb20cc5e7e025 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/features/AgentSetting/store/action.ts:316
        analytics.track({
          name: 'agent_meta_updated',
          properties: {
            assistant_avatar: mergedMeta.avatar,
            assistant_background_color: mergedMeta.backgroundColor,
            assistant_description: mergedMeta.description,
            assistant_name: mergedMeta.title,
            assistant_tags: mergedMeta.tags,
            is_inbox: id === 'inbox',
            session_id: id || 'unknown',
            timestamp: Date.now(),
            user_id: useUserStore.getState().user?.id || 'anonymous',
          },
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #32c6f45594394af1 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/features/Billboard/Carousel.tsx:146
      analytics?.track({
        name: 'billboard_cta_clicked',
        properties: {
          billboard_slug: billboardSlug,
          item_id: item.id,
          link_url: item.linkUrl,
          position,
          spm: 'billboard.cta.clicked',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #da49e4dd432c2841 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/features/Billboard/Carousel.tsx:245
      void analytics.track({
        name: 'billboard_served',
        properties: {
          billboard_slug: set.slug,
          item_count: set.items.length,
          spm: 'billboard.card.served',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #9bedac2928de9c0b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/features/Billboard/index.tsx:48
      analytics?.track({
        name: 'billboard_dismissed',
        properties: {
          billboard_slug: billboard.slug,
          item_count: billboard.items.length,
          spm: 'billboard.dismiss.clicked',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #01e56b4bee182505 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/features/User/UserLoginOrSignup/trackLoginOrSignupClicked.ts:23
    await analytics.track({
      name: 'login_or_signup_clicked',
      properties: {
        ...(lhCid && { lh_cid: lhCid }),
        ...(provider && { provider }),
        spm,
      },
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #d09c4dfb974eaead capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/libs/analytics/productUsageEvent.ts:27
    await analytics.track(event);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #4e5d669d57655b67 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/routes/(main)/home/_layout/Footer/index.tsx:177
        analytics?.track({ name: eventName, properties });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #b83ba8c82250f6ef capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/routes/(main)/home/_layout/Footer/index.tsx:188
        analytics?.track({
          name: 'home_footer_menu_clicked',
          properties: { key, spm: `homepage.footer.${key}.clicked` },
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #371c2390b82f6bc5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/routes/(main)/home/_layout/Footer/index.tsx:451
        analytics?.track({
          name: 'home_footer_menu_opened',
          properties: { keys: trackedMenuKeys.join(','), spm: 'homepage.footer.opened' },
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #e144c10afac0d357 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/routes/(mobile)/(home)/features/SessionListContent/List/index.tsx:65
                analytics?.track({
                  name: 'switch_session',
                  properties: {
                    assistant_name: session.meta?.title || 'Untitled Agent',
                    assistant_tags: session.meta?.tags || [],
                    group_id: sessionGroupId,
                    group_name: groupName,
                    session_id: id,
                    spm: 'homepage.chat.session_list_item.click',
                    user_id: userId || 'anonymous',
                  },
                });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #76c8cdab60e6e5ac capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/services/onboardingFeedback/index.ts:62
    options.analytics?.track({
      name: FEEDBACK_EVENT_NAME,
      properties: {
        rating: payload.rating,
        spm: FEEDBACK_SPM,
      },
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #dcbb6c101f56f45e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/services/onboardingMetrics/index.ts:34
    client.track({ name, properties });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #2ec7013fdb5e6214 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/store/agent/slices/agent/action.ts:152
      analytics.track({
        name: 'new_agent_created',
        properties: {
          agent_id: result.agentId,
          assistant_name: params.config?.title || 'Untitled Agent',
          assistant_tags: params.config?.tags || [],
          user_id: userId || 'anonymous',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a2e5de08cabf457c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/src/store/session/slices/session/action.ts:80
      analytics.track({
        name: 'new_agent_created',
        properties: {
          assistant_name: newSession.meta?.title || 'Untitled Agent',
          assistant_tags: newSession.meta?.tags || [],
          session_id: id,
          user_id: userId || 'anonymous',
        },
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #8e9258f67cde4a09 capability detected · no path traced Structural telemetry/analytics emit (event capture or batched event insert). Confirm user consent and what payload is sent to the destination.
repo/src/store/user/slices/common/action.ts:201
            analytics?.identify(data.userId || '', {
              email: data.email,
              firstName: data.firstName,
              lastName: data.lastName,
              username: data.username,
            });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 1119 low-confidence finding(s)
low env_fs Filesystem access. 251 locations
low env_fs Environment-variable access. 691 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 139 locations
low pii_flow PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime. 15 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 18 locations
low pii_flow test-only Excluded from app score #f1222cd1c2eaa69e A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent. Non-production path — not application runtime.
repo/scripts/docsWorkflow/utils.ts:96 · flow /tmp/closeopen-u_dp06n_/repo/scripts/docsWorkflow/utils.ts:87 → /tmp/closeopen-u_dp06n_/repo/scripts/docsWorkflow/utils.ts:96
    const response = await fetch(url, { headers });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

low pii_flow A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration. Non-production path — not application runtime. 3 locations
low pii_flow production #dfc71c3f102d7387 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration. Same-origin destination — not external exfiltration.
repo/src/features/Auth/SignIn/useSignIn.ts:158 · flow /tmp/closeopen-u_dp06n_/repo/src/features/Auth/SignIn/useSignIn.ts:154 → /tmp/closeopen-u_dp06n_/repo/src/features/Auth/SignIn/useSignIn.ts:158
      const response = await fetch('/api/auth/check-user', {
        body: JSON.stringify({ email: targetEmail }),
        headers: { 'Content-Type': 'application/json' },
        method: 'POST',
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

first-party (npm): packages/model-runtime

npm first-party
high pii_flow production #7b3cb09e0fd65f97 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/packages/model-runtime/src/providers/azureai/index.ts:67 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/azureai/index.ts:33 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/azureai/index.ts:67
      const response = this.client.path('/chat/completions').post({
        body: {
          messages: updatedMessages as OpenAI.ChatCompletionMessageParam[],
          model,
          ...params,
          stream: enableStreaming,
          temperature: model.includes('o3') || model.includes('o4') ? undefined : temperature,
          tool_choice: params.tools ? 'auto' : undefined,
          top_p: model.includes('o3') || model.includes('o4') ? undefined : top_p,
        },
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #28fc5ec4eea9faef A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/packages/model-runtime/src/providers/comfyui/index.ts:101 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/comfyui/index.ts:96 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/comfyui/index.ts:101
      const response = await fetch(`${appUrl}/webapi/create-image/comfyui`, {
        body: JSON.stringify({
          model: payload.model,
          options: this.options,
          params: payload.params,
        }),
        headers,
        method: 'POST',
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium pii_flow production #a3738f9561bed5b4 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:50 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:51 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:50
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #a94501824bf088db A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:166 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:167 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:166
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #7389da0d0f6c4835 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/aihubmix/index.ts:182 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/aihubmix/index.ts:163 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/aihubmix/index.ts:182
        headers: {
          'Authorization': `Bearer ${apiKey}`,
          'APP-Code': 'LobeHub',
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #fcd53627c6a511d0 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/bfl/createImage.ts:123 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/bfl/createImage.ts:125 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/bfl/createImage.ts:123
    headers: {
      'Content-Type': 'application/json',
      'x-key': options.apiKey,
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #17e7cd0e66c2f3df A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/bfl/createImage.ts:159 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/bfl/createImage.ts:161 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/bfl/createImage.ts:159
    headers: {
      'accept': 'application/json',
      'x-key': options.apiKey,
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #72c8c396920379f7 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/cloudflare/index.ts:95 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/cloudflare/index.ts:77 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/cloudflare/index.ts:95
        headers: { 'Content-Type': 'application/json', ...headers },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #c1968635cb3bb9f4 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/cloudflare/index.ts:157 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/cloudflare/index.ts:77 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/cloudflare/index.ts:157
      headers: {
        'Authorization': `Bearer ${this.apiKey}`,
        'Content-Type': 'application/json',
      },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #48bb73167716879c A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/comfyui/index.ts:107 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/comfyui/index.ts:96 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/comfyui/index.ts:107
        headers,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #edb9c13bc956def9 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/google/index.ts:490 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/google/index.ts:136 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/google/index.ts:490
        headers: {
          'x-goog-api-key': this.apiKey!,
        },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #4de846bb40d2fdac A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:54 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:55 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:54
    headers: {
      Authorization: `Bearer ${options.apiKey}`,
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #ff4d80c35b67a054 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:77 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:78 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:77
    headers: {
      Authorization: `Bearer ${options.apiKey}`,
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #21465fae845d1a0f A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:176 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:177 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/minimax/createVideo.ts:176
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #4188411fb93bcb76 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/nebius/index.ts:32 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/nebius/index.ts:34 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/nebius/index.ts:32
      headers: {
        Accept: 'application/json',
        Authorization: `Bearer ${client.apiKey}`,
      },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #df560194d06b89fc A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:40 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:41 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:40
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #8d3ec10dca7d71ce A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:125 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:126 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:125
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #f294b9393e164ff4 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/straico/index.ts:45 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/straico/index.ts:46 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/straico/index.ts:45
      headers: {
        Authorization: `Bearer ${client.apiKey}`,
      },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #e628b4d8b08ac920 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:77 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:78 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:77
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #4d27e86946fc7dc9 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:36 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:37 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:36
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #3ef79d79317d670f A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:136 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:137 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:136
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #547826b9f04bd75f A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/xai/createVideo.ts:34 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/xai/createVideo.ts:35 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/xai/createVideo.ts:34
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #83c75510c73a14ed A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/xai/createVideo.ts:126 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/xai/createVideo.ts:127 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/xai/createVideo.ts:126
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #4a541a921655bc34 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:38 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createImage.ts:39 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createImage.ts:38
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #125094f9d423df19 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:133 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createImage.ts:134 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createImage.ts:133
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #94786999f7567669 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:40 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:41 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:40
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #225a0086e6be52f2 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:146 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:147 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:146
    headers: {
      'Authorization': `Bearer ${options.apiKey}`,
      'Content-Type': 'application/json',
    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #471a74cd9b938cea A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/model-runtime/src/providers/zhipu/index.ts:221 · flow /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/index.ts:222 → /tmp/closeopen-u_dp06n_/repo/packages/model-runtime/src/providers/zhipu/index.ts:221
      headers: {
        'Authorization': `Bearer ${client.apiKey}`,
        'Bigmodel-Organization': 'lobehub',
        'Bigmodel-Project': 'lobechat',
      },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 430 low-confidence finding(s)
low env_fs Environment-variable access. 375 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 46 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 8 locations
low env_fs test-only Excluded from app score #47b2f02bff197bcb capability detected · no path traced Filesystem access.
repo/packages/model-runtime/src/utils/modelConfigImport.test.ts:13
        readFile(path.resolve(utilsDir, file), 'utf8'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/heterogeneous-agents

npm first-party
medium telemetry production #25f9c385334356e5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/agentStreamPipeline.ts:137
      const payload = this.codexTracker ? await this.codexTracker.track(raw as any) : raw;

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #bfd6a2db969768f7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:28
    await tracker.track({
      item: {
        changes: [
          { kind: 'update', path: updatePath },
          { kind: 'add', path: addPath },
        ],
        id: 'item_1',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #8753e899e26a58c5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:43
    const enriched = await tracker.track({
      item: {
        changes: [
          { kind: 'update', path: updatePath },
          { kind: 'add', path: addPath },
        ],
        id: 'item_1',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #4fb9db5fc704904d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:88
    await tracker.track({
      item: {
        changes: [],
        id: 'item_missing_snapshot',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #df1f901c8d75b937 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:99
    const enriched = await tracker.track({
      item: {
        changes: [{ kind: 'update', path: updatePath }],
        id: 'item_missing_snapshot',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #523a781f3eb87d37 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:124
    await tracker.track({
      item: {
        changes: [{ kind: 'update', path: updatePath }],
        id: 'item_missing_file_snapshot',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #05f5438cb0cca385 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:138
    const enriched = await tracker.track({
      item: {
        changes: [{ kind: 'update', linesAdded: 5, linesDeleted: 0, path: updatePath }],
        id: 'item_missing_file_snapshot',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #e1f6c3b2638cda68 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:167
    await tracker.track({
      item: {
        changes: [{ kind: 'rename', path: afterPath }],
        id: 'item_rename',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #19d7b9a4cae9223d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:178
    const enriched = await tracker.track({
      item: {
        changes: [{ kind: 'rename', path: afterPath }],
        id: 'item_rename',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #499c38c6ed619816 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:207
    await tracker.track({
      item: {
        changes: [{ kind: 'update', path: relativePath }],
        id: 'item_relative',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #79b29b2bc27c86f2 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:218
    const enriched = await tracker.track({
      item: {
        changes: [{ kind: 'update', path: relativePath }],
        id: 'item_relative',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #e28cb4174a89cafa capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:248
    await tracker.track({
      item: {
        changes: [{ kind: 'add', path: addPath }],
        id: 'item_plus_prefix',
        type: 'file_change',
      },
      type: 'item.started',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #176f7da1a2113a80 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/packages/heterogeneous-agents/src/spawn/codexFileChangeTracker.test.ts:259
    const enriched = await tracker.track({
      item: {
        changes: [{ kind: 'add', path: addPath }],
        id: 'item_plus_prefix',
        type: 'file_change',
      },
      type: 'item.completed',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 98 low-confidence finding(s)
low env_fs Filesystem access. 38 locations
low env_fs Environment-variable access. 59 locations
low egress production #62b6f0e2c37012ac capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/heterogeneous-agents/src/spawn/fileStoreImageUploader.ts:66
      const uploadRes = await fetch(presignedUrl, {
        body: buffer,
        headers: { 'Content-Type': mediaType },
        method: 'PUT',
      });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/web-crawler

npm first-party
medium pii_flow production #d64b905b97febbcc A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/web-crawler/src/crawImpl/exa.ts:38 · flow /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/exa.ts:25 → /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/exa.ts:38
          headers: {
            'Content-Type': 'application/json',
            'x-api-key': !apiKey ? '' : apiKey,
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #b5d6a0488b6c49ad A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/web-crawler/src/crawImpl/firecrawl.ts:67 · flow /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/firecrawl.ts:54 → /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/firecrawl.ts:67
          headers: {
            'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
            'Content-Type': 'application/json',
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #a41558e58208468a A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/web-crawler/src/crawImpl/jina.ts:18 · flow /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/jina.ts:11 → /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/jina.ts:18
          headers: {
            'Accept': 'application/json',
            'Authorization': token ? `Bearer ${token}` : '',
            'x-send-from': 'LobeChat Community',
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #848f81ba2919b918 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/web-crawler/src/crawImpl/search1api.ts:30 · flow /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/search1api.ts:19 → /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/search1api.ts:30
          headers: {
            'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
            'Content-Type': 'application/json',
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #f0b7635782b2b353 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
repo/packages/web-crawler/src/crawImpl/tavily.ts:39 · flow /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/tavily.ts:26 → /tmp/closeopen-u_dp06n_/repo/packages/web-crawler/src/crawImpl/tavily.ts:39
          headers: {
            'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
            'Content-Type': 'application/json',
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 82 low-confidence finding(s)
low env_fs Environment-variable access. 75 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 3 locations
low env_fs test-only Excluded from app score #f934c7843e9a2de0 capability detected · no path traced Filesystem access.
repo/packages/web-crawler/src/utils/htmlToMarkdown.test.ts:29
      const html = readFileSync(path.join(__dirname, `./html/${item.file}`), { encoding: 'utf8' });

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): apps/desktop/src/main

npm first-party
expand_more 193 low-confidence finding(s)
low egress Hardcoded external endpoint. Review what data is sent to this destination. 4 locations
low env_fs Filesystem access. 75 locations
low env_fs Environment-variable access. 101 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 13 locations

first-party (npm): e2e

npm first-party
expand_more 31 low-confidence finding(s)
low env_fs Environment-variable access. 24 locations
low egress test-only Excluded from app score #8ce24a40f94cec3f capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/e2e/scripts/setup.ts:283
    const response = await fetch(`http://localhost:${port}/chat`, { method: 'HEAD' });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low pii_flow A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent. Same-origin destination — not external exfiltration. 2 locations
low pii_flow User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration. Same-origin destination — not external exfiltration. 2 locations
low env_fs Filesystem access. 2 locations

first-party (npm): packages/agent-runtime

npm first-party
expand_more 3 low-confidence finding(s)
low env_fs Environment-variable access. 2 locations
low env_fs test-only Excluded from app score #10cdf05e821c072b capability detected · no path traced Filesystem access.
repo/packages/agent-runtime/src/agents/__tests__/GraphAgent.test.ts:104
    readFileSync(path.join(TEST_DIR, 'fixtures/goal-loop.graph.json'), 'utf8'),

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/agent-tracing

npm first-party
expand_more 20 low-confidence finding(s)
low env_fs Filesystem access. 16 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
low env_fs production #72ee427626fa0a9b capability detected · no path traced Environment-variable access.
repo/packages/agent-tracing/src/store/remote-store.ts:57
  if (process.env.TRACING_BASE_URL) return process.env.TRACING_BASE_URL;

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/builtin-tool-cloud-sandbox

npm first-party
expand_more 3 low-confidence finding(s)
low egress production #1cf5ca2223d20895 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/builtin-tool-cloud-sandbox/src/client/Render/ExportFile/index.tsx:34
        const response = await fetch(pluginState.downloadUrl);

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs Filesystem access. 2 locations

first-party (npm): packages/builtin-tool-creds

npm first-party
expand_more 1 low-confidence finding(s)
low env_fs production #386b0271a606c637 capability detected · no path traced Environment-variable access.
repo/packages/builtin-tool-creds/src/ExecutionRuntime/index.ts:171
      const appUrl = (process.env.APP_URL || OFFICIAL_URL).replace(/\/+$/, '');

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/builtin-tool-local-system

npm first-party

first-party (npm): packages/builtin-tool-skills

npm first-party

first-party (npm): packages/chat-adapter-feishu

npm first-party
expand_more 4 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations

first-party (npm): packages/chat-adapter-imessage

npm first-party
expand_more 1 low-confidence finding(s)
low egress production #cc9b6a84a7e87fbc capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/chat-adapter-imessage/src/api.ts:280
    return await fetch(url, { ...init, signal });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/chat-adapter-line

npm first-party
expand_more 3 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

first-party (npm): packages/chat-adapter-qq

npm first-party
expand_more 4 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
low egress production #eb17dcba40d46111 capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
repo/packages/chat-adapter-qq/src/api.ts:29
    const response = await fetch(AUTH_URL, {
      body: JSON.stringify({
        appId: this.appId,
        clientSecret: this.clientSecret,
      }),
      headers: { 'Content-Type': 'application/json' },
      method: 'POST',
    });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/connector-data

npm first-party
expand_more 1 low-confidence finding(s)
low egress production #1e01f09b3ff334f1 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/connector-data/src/github/graphql/client.ts:130
        response = await transport.request({ operation, query, variables });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/database

npm first-party
expand_more 35 low-confidence finding(s)
low env_fs Environment-variable access. 26 locations
low env_fs Filesystem access. 8 locations
low egress test-only Excluded from app score #43bfef74640729ec capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
repo/packages/database/src/models/__tests__/agentQuota.realAccount.e2e.test.ts:68
    const res = await fetch('https://api.anthropic.com/api/oauth/usage', {
      headers: {
        'Authorization': `Bearer ${readToken()}`,
        'User-Agent': 'claude-cli/2.1.198 (external, cli)',
        'anthropic-beta': 'oauth-2025-04-20',
      },
    });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/device-control

npm first-party
expand_more 36 low-confidence finding(s)
low env_fs Filesystem access. 36 locations

first-party (npm): packages/device-gateway-client

npm first-party
expand_more 1 low-confidence finding(s)
low egress production #5b7e435eafac5ec7 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/device-gateway-client/src/http.ts:290
    return fetch(`${this.gatewayUrl}${path}`, {
      body: JSON.stringify(body),
      headers: {
        'Authorization': `Bearer ${this.serviceToken}`,
        'Content-Type': 'application/json',
      },
      method: 'POST',
      ...(options?.timeout ? { signal: AbortSignal.timeout(options.timeout) } : {}),
    });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/device-sandbox

npm first-party

first-party (npm): packages/edge-config

npm first-party
expand_more 1 low-confidence finding(s)
low egress production #e830f51513d338b4 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/edge-config/src/index.ts:30
    return this.client.get<EdgeConfigData[K]>(key);

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/electron-server-ipc

npm first-party
expand_more 2 low-confidence finding(s)

first-party (npm): packages/env

npm first-party
expand_more 431 low-confidence finding(s)
low env_fs Environment-variable access. 431 locations

first-party (npm): packages/local-file-shell

npm first-party
expand_more 79 low-confidence finding(s)
low env_fs Filesystem access. 79 locations

first-party (npm): packages/memory-user-memory

npm first-party
expand_more 5 low-confidence finding(s)
low env_fs Environment-variable access. 3 locations
low egress test-only Excluded from app score #e777b043cec94cf8 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/memory-user-memory/benchmarks/locomo/run.ts:23
  const res = await fetch(new URL(path, baseUrl).toString(), {
    body: JSON.stringify(body),
    headers: {
      'Content-Type': 'application/json',
      ...webhookHeaders,
    },
    method: 'POST',
  });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs production #7bcd14b66714b174 capability detected · no path traced Filesystem access.
repo/packages/memory-user-memory/src/converters/locomo.ts:176
  const raw = readFileSync(absPath, 'utf8');

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/model-bank

npm first-party
expand_more 1 low-confidence finding(s)
low env_fs test-only Excluded from app score #f2b6c1878fb83057 capability detected · no path traced Filesystem access.
repo/packages/model-bank/src/exports.test.ts:12
  const packageJson = JSON.parse(readFileSync(packageJsonPath, 'utf8')) as {

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (npm): packages/openapi

npm first-party
expand_more 5 low-confidence finding(s)
low env_fs production #1fe4f1655fde56ac capability detected · no path traced Filesystem access.
repo/packages/openapi/src/helpers/file.ts:118
          const bin = fs.readFileSync((f as any).filepath);

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Environment-variable access. 4 locations

first-party (npm): packages/python-interpreter

npm first-party
expand_more 5 low-confidence finding(s)
low env_fs Filesystem access. 4 locations
low egress production #caebac53cdde0a71 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/python-interpreter/src/worker.ts:173
      const buffer = await fetch(url, { cache: 'force-cache' }).then((res) => res.arrayBuffer());

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/trpc

npm first-party
expand_more 5 low-confidence finding(s)
low egress production #8cff4bdcf9d9ee2d capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/packages/trpc/src/client/lambda.ts:128
    const response = await fetch(input, { ...init, credentials: 'include' });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs Environment-variable access. 4 locations

first-party (npm): packages/utils

npm first-party
expand_more 8 low-confidence finding(s)

Skipped dependencies

Production

  • first-party (npm): apps/server prod — scan budget exceeded
  • @ant-design/icons prod — scan budget exceeded
  • @ant-design/pro-components prod — scan budget exceeded
  • @anthropic-ai/sdk prod — scan budget exceeded
  • @atlaskit/pragmatic-drag-and-drop prod — scan budget exceeded
  • @atlaskit/pragmatic-drag-and-drop-hitbox prod — scan budget exceeded
  • @aws-sdk/client-bedrock-runtime prod — scan budget exceeded
  • @aws-sdk/client-s3 prod — scan budget exceeded
  • @aws-sdk/s3-request-presigner prod — scan budget exceeded
  • @azure-rest/ai-inference prod — scan budget exceeded
  • @azure/core-auth prod — scan budget exceeded
  • @better-auth/expo prod — scan budget exceeded
  • @better-auth/passkey prod — scan budget exceeded
  • @cfworker/json-schema prod — scan budget exceeded
  • @chat-adapter/discord prod — scan budget exceeded
  • @chat-adapter/slack prod — scan budget exceeded
  • @chat-adapter/state-ioredis prod — scan budget exceeded
  • @chat-adapter/telegram prod — scan budget exceeded
  • @codesandbox/sandpack-react prod — scan budget exceeded
  • @composio/core prod — scan budget exceeded
  • @discordjs/rest prod — scan budget exceeded
  • @dnd-kit/core prod — scan budget exceeded
  • @dnd-kit/sortable prod — scan budget exceeded
  • @dnd-kit/utilities prod — scan budget exceeded
  • @emoji-mart/data prod — scan budget exceeded
  • @emoji-mart/react prod — scan budget exceeded
  • @emotion/react prod — scan budget exceeded
  • @fal-ai/client prod — scan budget exceeded
  • @floating-ui/react prod — scan budget exceeded
  • @formkit/auto-animate prod — scan budget exceeded
  • @google/genai prod — scan budget exceeded
  • @henrygd/queue prod — scan budget exceeded
  • @huggingface/inference prod — scan budget exceeded
  • @icons-pack/react-simple-icons prod — scan budget exceeded
  • @khmyznikov/pwa-install prod — scan budget exceeded
  • @larksuiteoapi/node-sdk prod — scan budget exceeded
  • @lexical/utils prod — scan budget exceeded
  • @lobehub/analytics prod — scan budget exceeded
  • @lobehub/charts prod — scan budget exceeded
  • @lobehub/editor prod — scan budget exceeded
  • @lobehub/icons prod — scan budget exceeded
  • @lobehub/market-sdk prod — scan budget exceeded
  • @lobehub/tts prod — scan budget exceeded
  • @lobehub/ui prod — scan budget exceeded
  • @modelcontextprotocol/sdk prod — scan budget exceeded
  • @napi-rs/canvas prod — scan budget exceeded
  • @neondatabase/serverless prod — scan budget exceeded
  • @next/third-parties prod — scan budget exceeded
  • @opentelemetry/auto-instrumentations-node prod — scan budget exceeded
  • @opentelemetry/exporter-jaeger prod — scan budget exceeded
  • @opentelemetry/resources prod — scan budget exceeded
  • @opentelemetry/sdk-metrics prod — scan budget exceeded
  • @opentelemetry/winston-transport prod — scan budget exceeded
  • @pierre/trees prod — scan budget exceeded
  • @react-pdf/renderer prod — scan budget exceeded
  • @react-three/drei prod — scan budget exceeded
  • @react-three/fiber prod — scan budget exceeded
  • @saintno/comfyui-sdk prod — scan budget exceeded
  • @t3-oss/env-core prod — scan budget exceeded
  • @t3-oss/env-nextjs prod — scan budget exceeded
  • @tanstack/react-query prod — scan budget exceeded
  • @trpc/client prod — scan budget exceeded
  • @trpc/next prod — scan budget exceeded
  • @trpc/react-query prod — scan budget exceeded
  • @trpc/server prod — scan budget exceeded
  • @upstash/qstash prod — scan budget exceeded
  • @upstash/workflow prod — scan budget exceeded
  • @vercel/analytics prod — scan budget exceeded
  • @vercel/edge-config prod — scan budget exceeded
  • @vercel/functions prod — scan budget exceeded
  • @vercel/speed-insights prod — scan budget exceeded
  • @virtuoso.dev/masonry prod — scan budget exceeded
  • @xterm/addon-fit prod — scan budget exceeded
  • @xterm/addon-webgl prod — scan budget exceeded
  • @xterm/xterm prod — scan budget exceeded
  • @zumer/snapdom prod — scan budget exceeded
  • ahooks prod — scan budget exceeded
  • antd prod — scan budget exceeded
  • antd-style prod — scan budget exceeded
  • async-retry prod — scan budget exceeded
  • bcryptjs prod — scan budget exceeded
  • better-auth prod — scan budget exceeded
  • brotli-wasm prod — scan budget exceeded
  • buffer.js prod — scan budget exceeded
  • chat prod — scan budget exceeded
  • chroma-js prod — scan budget exceeded
  • class-variance-authority prod — scan budget exceeded
  • cmdk prod — scan budget exceeded
  • cookie prod — scan budget exceeded
  • countries-and-timezones prod — scan budget exceeded
  • d3-dsv prod — scan budget exceeded
  • dayjs prod — scan budget exceeded
  • debug prod — scan budget exceeded
  • dexie prod — scan budget exceeded
  • diff prod — scan budget exceeded
  • discord-api-types prod — scan budget exceeded
  • drizzle-orm prod — scan budget exceeded
  • drizzle-zod prod — scan budget exceeded
  • epub2 prod — scan budget exceeded
  • es-toolkit prod — scan budget exceeded
  • expo-server-sdk prod — scan budget exceeded
  • fast-deep-equal prod — scan budget exceeded
  • fflate prod — scan budget exceeded
  • ffmpeg-static prod — scan budget exceeded
  • file-type prod — scan budget exceeded
  • fuse.js prod — scan budget exceeded
  • gray-matter prod — scan budget exceeded
  • hono prod — scan budget exceeded
  • html-to-text prod — scan budget exceeded
  • i18next prod — scan budget exceeded
  • i18next-browser-languagedetector prod — scan budget exceeded
  • i18next-resources-to-backend prod — scan budget exceeded
  • immer prod — scan budget exceeded
  • ioredis prod — scan budget exceeded
  • jose prod — scan budget exceeded
  • js-sha256 prod — scan budget exceeded
  • jsondiffpatch prod — scan budget exceeded
  • jsonl-parse-stringify prod — scan budget exceeded
  • langfuse prod — scan budget exceeded
  • langfuse-core prod — scan budget exceeded
  • lexical prod — scan budget exceeded
  • lucide-react prod — scan budget exceeded
  • mammoth prod — scan budget exceeded
  • marked prod — scan budget exceeded
  • mdast-util-to-markdown prod — scan budget exceeded
  • motion prod — scan budget exceeded
  • nanoid prod — scan budget exceeded
  • next prod — scan budget exceeded
  • next-mdx-remote prod — scan budget exceeded
  • next-themes prod — scan budget exceeded
  • nextjs-toploader prod — scan budget exceeded
  • node-machine-id prod — scan budget exceeded
  • nodemailer prod — scan budget exceeded
  • numeral prod — scan budget exceeded
  • nuqs prod — scan budget exceeded
  • octokit prod — scan budget exceeded
  • officeparser prod — scan budget exceeded
  • ogl prod — scan budget exceeded
  • oidc-provider prod — scan budget exceeded
  • ollama prod — scan budget exceeded
  • openai prod — scan budget exceeded
  • openapi-fetch prod — scan budget exceeded
  • partial-json prod — scan budget exceeded
  • path-browserify-esm prod — scan budget exceeded
  • pathe prod — scan budget exceeded
  • pdf-parse prod — scan budget exceeded
  • pdfjs-dist prod — scan budget exceeded
  • pdfkit prod — scan budget exceeded
  • pg prod — scan budget exceeded
  • pinyin-pro prod — scan budget exceeded
  • plaiceholder prod — scan budget exceeded
  • polished prod — scan budget exceeded
  • posthog-js prod — scan budget exceeded
  • pure-rand prod — scan budget exceeded
  • pwa-install-handler prod — scan budget exceeded
  • query-string prod — scan budget exceeded
  • random-words prod — scan budget exceeded
  • rc-util prod — scan budget exceeded
  • react prod — scan budget exceeded
  • react-confetti prod — scan budget exceeded
  • react-dom prod — scan budget exceeded
  • react-fast-marquee prod — scan budget exceeded
  • react-hotkeys-hook prod — scan budget exceeded
  • react-i18next prod — scan budget exceeded
  • react-lazy-load prod — scan budget exceeded
  • react-markdown prod — scan budget exceeded
  • react-pdf prod — scan budget exceeded
  • react-responsive prod — scan budget exceeded
  • react-rnd prod — scan budget exceeded
  • react-router prod — scan budget exceeded
  • react-scan prod — scan budget exceeded
  • react-virtuoso prod — scan budget exceeded
  • react-wrap-balancer prod — scan budget exceeded
  • remark prod — scan budget exceeded
  • remark-gfm prod — scan budget exceeded
  • remark-html prod — scan budget exceeded
  • remove-markdown prod — scan budget exceeded
  • resend prod — scan budget exceeded
  • resolve-accept-language prod — scan budget exceeded
  • rtl-detect prod — scan budget exceeded
  • semver prod — scan budget exceeded
  • sharp prod — scan budget exceeded
  • shiki prod — scan budget exceeded
  • stripe prod — scan budget exceeded
  • superjson prod — scan budget exceeded
  • svix prod — scan budget exceeded
  • swr prod — scan budget exceeded
  • three prod — scan budget exceeded
  • tokenx prod — scan budget exceeded
  • ts-md5 prod — scan budget exceeded
  • ua-parser-js prod — scan budget exceeded
  • undici prod — scan budget exceeded
  • unist-builder prod — scan budget exceeded
  • url-join prod — scan budget exceeded
  • use-merge-value prod — scan budget exceeded
  • uuid prod — scan budget exceeded
  • virtua prod — scan budget exceeded
  • word-extractor prod — scan budget exceeded
  • ws prod — scan budget exceeded
  • xast-util-to-xml prod — scan budget exceeded
  • xastscript prod — scan budget exceeded