Close Open Privacy Scan
App Privacy Score
High risk · 2764 finding(s)
Based on: 97 first-party package(s) · 0/200 deps analyzed
Dependency score: 100 (Low risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Confirmed data exfiltration in application code
External domains:
302.aia.comagent-gateway.lobehub.comai-gateway.vercel.shai-userxxxxxxxxxx.services.ai.azure.comai.360.cnai.360.comai.azure.comai.gitee.comai.google.devai.meta.comaihubmix.comalipaytbox.yuque.comampcode.comanalytics.umami.isanthropic.comapi-data.line.meapi-inference.modelscope.cnapi.302.aiapi.360.cnapi.abc.comapi.ai21.comapi.anthropic.comapi.baichuan-ai.comapi.bfl.aiapi.bochaai.comapi.cerebras.aiapi.cloudflare.comapi.cohere.aiapi.cohere.comapi.cometapi.comapi.deepseek.comapi.exa.aiapi.firecrawl.devapi.fireworks.aiapi.github.comapi.githubcopilot.comapi.groq.comapi.kimi.comapi.line.meapi.lingyiwanwu.comapi.lkeap.cloud.tencent.comapi.longcat.chatapi.minimax.ioapi.minimaxi.comapi.mistral.aiapi.moonshot.cnapi.novita.aiapi.openai.comapi.perplexity.aiapi.ppinfra.comapi.replicate.comapi.sambanova.aiapi.search.brave.comapi.search1api.comapi.sgroup.qq.comapi.siliconflow.cnapi.slack.comapi.stepfun.comapi.straico.comapi.studio.nebius.comapi.tavily.comapi.tbox.cnapi.telegram.orgapi.together.xyzapi.upstage.aiapi.v0.devapi.x.aiapi.xiaomimimo.comapig.console.aliyun.comapp.lobehub.comapp.posthog.comark.cn-beijing.volces.comarxiv.orgauth.openai.comauth.x.aiazure.microsoft.combfl.aibluebubbles.appbots.qq.combuild.nvidia.comcdn.jsdelivr.netcdn.tailwindcss.comcerebras.aichat-plugins.lobehub.comchat-preview.lobehub.comchat.intern-ai.org.cnchatapi.akash.networkchatgpt.comchrome.browserless.ioclaude.aicloud.baidu.comcloud.google.comcloud.infini-ai.comcloud.langfuse.comcloud.sambanova.aicloud.tencent.comcloud.zidongtaichu.comcoding.dashscope.aliyuncs.comcohere.comcometapi.comcomposio.devconsole.bce.baidu.comconsole.cloud.google.comconsole.cloud.tencent.comconsole.groq.comcvpr.thecvf.comdashscope.aliyuncs.comdatatracker.ietf.orgdeepsearch.jina.aideepseek.comdeveloper.mozilla.orgdeveloper.qiniu.comdevelopers.cloudflare.comdevelopers.line.bizdevelopers.upstage.aidevice-gateway.lobehub.comdiscord.comdiscord.ggdocs.ai21.comdocs.aihubmix.comdocs.anthropic.comdocs.aws.amazon.comdocs.cohere.comdocs.mistral.aidocs.perplexity.aidocs.together.aidocs.vllm.aidocs.x.aidocs.z.aifal.aifireworks.aigenerativelanguage.googleapis.comgithub.comgroq.comhelp.aliyun.comhigress.cnhub-apac-1.lobeobjects.spacehuggingface.cohunyuan.tencent.comicons.duckduckgo.comilinkai.weixin.qq.cominference-docs.cerebras.aiinference.readthedocs.iointegrate.api.nvidia.cominternlm.intern-ai.org.cnjina.aikagi.comlearn.chatgpt.comlearn.microsoft.comling.tbox.cnlmstudio.ailobe.lilobechat.comlobehub.comlocal.filelongcat.chatmarket.lobehub.commedium.commistral.aimodels.devmodels.github.aimodelscope.cnnebius.comnovac2c.cdn.weixin.qq.comnovita.ainpmmirror.comollama.comopen.bigmodel.cnopen.feishu.cnopen.larksuite.comopenai.comopenai.qiniu.comopencode.aiopenrouter.aiplatform.baichuan-ai.complatform.deepseek.complatform.lingyiwanwu.complatform.minimax.ioplatform.minimaxi.complatform.moonshot.aiplatform.openai.complatform.sensenova.cnplatform.stepfun.complatform.xiaomimimo.complausible.ioplay.google.complugin.anspire.cnppinfra.comq.qq.comqianfan.baidubce.comqstash.upstash.ior.jina.air.jinaai.cnraw.githubusercontent.comregistry.npmjs.orgregistry.npmmirror.comreplicate.comrouter.huggingface.cos.jina.ais.jinaai.cnsandbox.api.sgroup.qq.comscribe.ripsiliconflow.cnslack.comsogou.comspark-api-open.xf-yun.comstepfun.comstraico.comstudio.ai21.comstudio.nebius.comt.metestflight.apple.comtoken.sensenova.cntokenhub.tencentmaas.comupstage.aiv0.devvercel.comwallstreetcn.comwanqing.streamlakeapi.comworkflow-run-guard.localwww.aliyun.comwww.bing.comwww.comfy.orgwww.google.comwww.googleapis.comwww.lingyiwanwu.comwww.minimaxi.comwww.moonshot.aiwww.perplexity.aiwww.qiniu.comwww.qiumiwu.comwww.reddit.comwww.search1api.comwww.sensenova.cnwww.streamlake.comwww.together.aiwww.volcengine.comwww.w3.orgwww.xfyun.cnwww.youtube.comx.aix.comxinghuo.xfyun.cnyour-proxy-url.comyour-resource.cognitiveservices.azure.comyour-server.comyour.new-api-provider.comz.aizenmux.aizhipuai.cnzhuanlan.zhihu.com
- 1source
repo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:120 - 2sink
repo/apps/server/src/services/oauthDeviceFlow/providers/chatGPT.ts:148
- 1source
repo/packages/model-runtime/src/providers/azureai/index.ts:33 - 2sink
repo/packages/model-runtime/src/providers/azureai/index.ts:67
- 1source
repo/packages/model-runtime/src/providers/comfyui/index.ts:96 - 2sink
repo/packages/model-runtime/src/providers/comfyui/index.ts:101
- 1source
repo/apps/server/src/routers/async/caller.ts:23 - 2sink
repo/apps/server/src/routers/async/caller.ts:29
- 1source
repo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:48 - 2sink
repo/apps/server/src/services/agentRuntime/hooks/HookDispatcher.ts:47
- 1source
repo/apps/server/src/services/bot/BotMessageRouter.ts:780 - 2sink
repo/apps/server/src/services/bot/BotMessageRouter.ts:798
- 1source
repo/apps/server/src/services/desktopRelease/index.ts:120 - 2sink
repo/apps/server/src/services/desktopRelease/index.ts:123
- 1source
repo/apps/server/src/services/search/impls/anspire/index.ts:74 - 2sink
repo/apps/server/src/services/search/impls/anspire/index.ts:72
- 1source
repo/apps/server/src/services/search/impls/bocha/index.ts:64 - 2sink
repo/apps/server/src/services/search/impls/bocha/index.ts:63
- 1source
repo/apps/server/src/services/search/impls/brave/index.ts:70 - 2sink
repo/apps/server/src/services/search/impls/brave/index.ts:67
- 1source
repo/apps/server/src/services/search/impls/exa/index.ts:69 - 2sink
repo/apps/server/src/services/search/impls/exa/index.ts:67
- 1source
repo/apps/server/src/services/search/impls/firecrawl/index.ts:69 - 2sink
repo/apps/server/src/services/search/impls/firecrawl/index.ts:68
- 1source
repo/apps/server/src/services/search/impls/jina/index.ts:48 - 2sink
repo/apps/server/src/services/search/impls/jina/index.ts:46
- 1source
repo/apps/server/src/services/search/impls/kagi/index.ts:52 - 2sink
repo/apps/server/src/services/search/impls/kagi/index.ts:51
- 1source
repo/apps/server/src/services/search/impls/search1api/index.ts:85 - 2sink
repo/apps/server/src/services/search/impls/search1api/index.ts:84
- 1source
repo/apps/server/src/services/search/impls/tavily/index.ts:63 - 2sink
repo/apps/server/src/services/search/impls/tavily/index.ts:62
- 1source
repo/apps/server/src/workflows/runGuard/qstashCancel.ts:79 - 2sink
repo/apps/server/src/workflows/runGuard/qstashCancel.ts:95
- 1source
repo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:43 - 2sink
repo/src/app/(backend)/webapi/models/[provider]/pricing/route.ts:64
- 1source
repo/packages/web-crawler/src/crawImpl/exa.ts:25 - 2sink
repo/packages/web-crawler/src/crawImpl/exa.ts:38
- 1source
repo/packages/web-crawler/src/crawImpl/firecrawl.ts:54 - 2sink
repo/packages/web-crawler/src/crawImpl/firecrawl.ts:67
- 1source
repo/packages/web-crawler/src/crawImpl/jina.ts:11 - 2sink
repo/packages/web-crawler/src/crawImpl/jina.ts:18
- 1source
repo/packages/web-crawler/src/crawImpl/search1api.ts:19 - 2sink
repo/packages/web-crawler/src/crawImpl/search1api.ts:30
- 1source
repo/packages/web-crawler/src/crawImpl/tavily.ts:26 - 2sink
repo/packages/web-crawler/src/crawImpl/tavily.ts:39
- 1source
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:51 - 2sink
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:50
- 1source
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:167 - 2sink
repo/packages/model-runtime/src/core/openaiCompatibleFactory/createVideo.ts:166
- 1source
repo/packages/model-runtime/src/providers/aihubmix/index.ts:163 - 2sink
repo/packages/model-runtime/src/providers/aihubmix/index.ts:182
- 1source
repo/packages/model-runtime/src/providers/bfl/createImage.ts:125 - 2sink
repo/packages/model-runtime/src/providers/bfl/createImage.ts:123
- 1source
repo/packages/model-runtime/src/providers/bfl/createImage.ts:161 - 2sink
repo/packages/model-runtime/src/providers/bfl/createImage.ts:159
- 1source
repo/packages/model-runtime/src/providers/cloudflare/index.ts:77 - 2sink
repo/packages/model-runtime/src/providers/cloudflare/index.ts:95
- 1source
repo/packages/model-runtime/src/providers/cloudflare/index.ts:77 - 2sink
repo/packages/model-runtime/src/providers/cloudflare/index.ts:157
- 1source
repo/packages/model-runtime/src/providers/comfyui/index.ts:96 - 2sink
repo/packages/model-runtime/src/providers/comfyui/index.ts:107
- 1source
repo/packages/model-runtime/src/providers/google/index.ts:136 - 2sink
repo/packages/model-runtime/src/providers/google/index.ts:490
- 1source
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:55 - 2sink
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:54
- 1source
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:78 - 2sink
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:77
- 1source
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:177 - 2sink
repo/packages/model-runtime/src/providers/minimax/createVideo.ts:176
- 1source
repo/packages/model-runtime/src/providers/nebius/index.ts:34 - 2sink
repo/packages/model-runtime/src/providers/nebius/index.ts:32
- 1source
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:41 - 2sink
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:40
- 1source
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:126 - 2sink
repo/packages/model-runtime/src/providers/siliconcloud/createVideo.ts:125
- 1source
repo/packages/model-runtime/src/providers/straico/index.ts:46 - 2sink
repo/packages/model-runtime/src/providers/straico/index.ts:45
- 1source
repo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:78 - 2sink
repo/packages/model-runtime/src/providers/volcengine/video/createVideo.ts:77
- 1source
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:37 - 2sink
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:36
- 1source
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:137 - 2sink
repo/packages/model-runtime/src/providers/wenxin/createVideo.ts:136
- 1source
repo/packages/model-runtime/src/providers/xai/createVideo.ts:35 - 2sink
repo/packages/model-runtime/src/providers/xai/createVideo.ts:34
- 1source
repo/packages/model-runtime/src/providers/xai/createVideo.ts:127 - 2sink
repo/packages/model-runtime/src/providers/xai/createVideo.ts:126
- 1source
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:39 - 2sink
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:38
- 1source
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:134 - 2sink
repo/packages/model-runtime/src/providers/zhipu/createImage.ts:133
- 1source
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:41 - 2sink
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:40
- 1source
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:147 - 2sink
repo/packages/model-runtime/src/providers/zhipu/createVideo.ts:146
- 1source
repo/packages/model-runtime/src/providers/zhipu/index.ts:222 - 2sink
repo/packages/model-runtime/src/providers/zhipu/index.ts:221
</> First-Party Code
first-party (npm)
npm first-party body: new URLSearchParams({
client_id: config.clientId,
code: authorization.authorization_code,
code_verifier: authorization.code_verifier,
grant_type: 'authorization_code',
redirect_uri: `${issuer}/deviceauth/callback`,
}).toString(),
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
headers,
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
...(process.env.VERCEL_AUTOMATION_BYPASS_SECRET && {
'x-vercel-protection-bypass': process.env.VERCEL_AUTOMATION_BYPASS_SECRET,
}),
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
await thread.post(text);
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
...(token ? { Authorization: `Bearer ${token}` } : {}),
'Accept': 'application/vnd.github+json',
'User-Agent': 'lobehub-server',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Accept': '*/*',
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Connection': 'keep-alive ',
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Accept': 'application/json',
'Accept-Encoding': 'gzip',
'X-Subscription-Token': this.apiKey ? this.apiKey : '',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Content-Type': 'application/json',
'x-api-key': this.apiKey ? this.apiKey : '',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Accept': 'application/json',
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Content-Type': 'application/json',
'X-Respond-With': 'no-content',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
Authorization: this.apiKey ? `Bot ${this.apiKey}` : '',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': this.apiKey ? `Bearer ${this.apiKey}` : '',
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
analytics?.identify(user.id, {
email: user.email ?? undefined,
firstName: user.firstName ?? undefined,
lastName: user.lastName ?? undefined,
phone: user.phone ?? undefined,
username: user.username ?? undefined,
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'user_register_completed',
properties: {
spm: 'user_service.init_user.user_created',
},
userId: user.id,
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
headers: {
'Authorization': `Bearer ${token}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
return ssrfSafeFetch(pricingUrl, { headers: currentHeaders });
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
analytics.track({
name: 'main_page_view',
properties: {
spm: 'homepage.main_page.view',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics.track({
name: 'agent_meta_updated',
properties: {
assistant_avatar: mergedMeta.avatar,
assistant_background_color: mergedMeta.backgroundColor,
assistant_description: mergedMeta.description,
assistant_name: mergedMeta.title,
assistant_tags: mergedMeta.tags,
is_inbox: id === 'inbox',
session_id: id || 'unknown',
timestamp: Date.now(),
user_id: useUserStore.getState().user?.id || 'anonymous',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'billboard_cta_clicked',
properties: {
billboard_slug: billboardSlug,
item_id: item.id,
link_url: item.linkUrl,
position,
spm: 'billboard.cta.clicked',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
void analytics.track({
name: 'billboard_served',
properties: {
billboard_slug: set.slug,
item_count: set.items.length,
spm: 'billboard.card.served',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'billboard_dismissed',
properties: {
billboard_slug: billboard.slug,
item_count: billboard.items.length,
spm: 'billboard.dismiss.clicked',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await analytics.track({
name: 'login_or_signup_clicked',
properties: {
...(lhCid && { lh_cid: lhCid }),
...(provider && { provider }),
spm,
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await analytics.track(event);
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({ name: eventName, properties });
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'home_footer_menu_clicked',
properties: { key, spm: `homepage.footer.${key}.clicked` },
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'home_footer_menu_opened',
properties: { keys: trackedMenuKeys.join(','), spm: 'homepage.footer.opened' },
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.track({
name: 'switch_session',
properties: {
assistant_name: session.meta?.title || 'Untitled Agent',
assistant_tags: session.meta?.tags || [],
group_id: sessionGroupId,
group_name: groupName,
session_id: id,
spm: 'homepage.chat.session_list_item.click',
user_id: userId || 'anonymous',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
options.analytics?.track({
name: FEEDBACK_EVENT_NAME,
properties: {
rating: payload.rating,
spm: FEEDBACK_SPM,
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
client.track({ name, properties });
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics.track({
name: 'new_agent_created',
properties: {
agent_id: result.agentId,
assistant_name: params.config?.title || 'Untitled Agent',
assistant_tags: params.config?.tags || [],
user_id: userId || 'anonymous',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics.track({
name: 'new_agent_created',
properties: {
assistant_name: newSession.meta?.title || 'Untitled Agent',
assistant_tags: newSession.meta?.tags || [],
session_id: id,
user_id: userId || 'anonymous',
},
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
analytics?.identify(data.userId || '', {
email: data.email,
firstName: data.firstName,
lastName: data.lastName,
username: data.username,
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 1119 low-confidence finding(s)
low env_fs — Filesystem access. 251 locations
low env_fs — Environment-variable access. 691 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 139 locations
low pii_flow — PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime. 15 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 18 locations
const response = await fetch(url, { headers });
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
low pii_flow — A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration. Non-production path — not application runtime. 3 locations
const response = await fetch('/api/auth/check-user', {
body: JSON.stringify({ email: targetEmail }),
headers: { 'Content-Type': 'application/json' },
method: 'POST',
});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
first-party (npm): packages/model-runtime
npm first-party const response = this.client.path('/chat/completions').post({
body: {
messages: updatedMessages as OpenAI.ChatCompletionMessageParam[],
model,
...params,
stream: enableStreaming,
temperature: model.includes('o3') || model.includes('o4') ? undefined : temperature,
tool_choice: params.tools ? 'auto' : undefined,
top_p: model.includes('o3') || model.includes('o4') ? undefined : top_p,
},
});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
const response = await fetch(`${appUrl}/webapi/create-image/comfyui`, {
body: JSON.stringify({
model: payload.model,
options: this.options,
params: payload.params,
}),
headers,
method: 'POST',
});
User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.
Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${apiKey}`,
'APP-Code': 'LobeHub',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Content-Type': 'application/json',
'x-key': options.apiKey,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'accept': 'application/json',
'x-key': options.apiKey,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: { 'Content-Type': 'application/json', ...headers },
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${this.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers,
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'x-goog-api-key': this.apiKey!,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
Authorization: `Bearer ${options.apiKey}`,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
Authorization: `Bearer ${options.apiKey}`,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
Accept: 'application/json',
Authorization: `Bearer ${client.apiKey}`,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
Authorization: `Bearer ${client.apiKey}`,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${options.apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': `Bearer ${client.apiKey}`,
'Bigmodel-Organization': 'lobehub',
'Bigmodel-Project': 'lobechat',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
expand_more 430 low-confidence finding(s)
low env_fs — Environment-variable access. 375 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 46 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 8 locations
readFile(path.resolve(utilsDir, file), 'utf8'),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/heterogeneous-agents
npm first-party const payload = this.codexTracker ? await this.codexTracker.track(raw as any) : raw;
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [
{ kind: 'update', path: updatePath },
{ kind: 'add', path: addPath },
],
id: 'item_1',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [
{ kind: 'update', path: updatePath },
{ kind: 'add', path: addPath },
],
id: 'item_1',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [],
id: 'item_missing_snapshot',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [{ kind: 'update', path: updatePath }],
id: 'item_missing_snapshot',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [{ kind: 'update', path: updatePath }],
id: 'item_missing_file_snapshot',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [{ kind: 'update', linesAdded: 5, linesDeleted: 0, path: updatePath }],
id: 'item_missing_file_snapshot',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [{ kind: 'rename', path: afterPath }],
id: 'item_rename',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [{ kind: 'rename', path: afterPath }],
id: 'item_rename',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [{ kind: 'update', path: relativePath }],
id: 'item_relative',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [{ kind: 'update', path: relativePath }],
id: 'item_relative',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
await tracker.track({
item: {
changes: [{ kind: 'add', path: addPath }],
id: 'item_plus_prefix',
type: 'file_change',
},
type: 'item.started',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
const enriched = await tracker.track({
item: {
changes: [{ kind: 'add', path: addPath }],
id: 'item_plus_prefix',
type: 'file_change',
},
type: 'item.completed',
});
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
expand_more 98 low-confidence finding(s)
low env_fs — Filesystem access. 38 locations
low env_fs — Environment-variable access. 59 locations
const uploadRes = await fetch(presignedUrl, {
body: buffer,
headers: { 'Content-Type': mediaType },
method: 'PUT',
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/web-crawler
npm first-party headers: {
'Content-Type': 'application/json',
'x-api-key': !apiKey ? '' : apiKey,
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Accept': 'application/json',
'Authorization': token ? `Bearer ${token}` : '',
'x-send-from': 'LobeChat Community',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
headers: {
'Authorization': !apiKey ? '' : `Bearer ${apiKey}`,
'Content-Type': 'application/json',
},
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
expand_more 82 low-confidence finding(s)
low env_fs — Environment-variable access. 75 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 3 locations
const html = readFileSync(path.join(__dirname, `./html/${item.file}`), { encoding: 'utf8' });
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): apps/desktop/src/main
npm first-partyexpand_more 193 low-confidence finding(s)
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 4 locations
low env_fs — Filesystem access. 75 locations
low env_fs — Environment-variable access. 101 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 13 locations
first-party (npm): e2e
npm first-partyexpand_more 31 low-confidence finding(s)
low env_fs — Environment-variable access. 24 locations
const response = await fetch(`http://localhost:${port}/chat`, { method: 'HEAD' });
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
low pii_flow — A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent. Same-origin destination — not external exfiltration. 2 locations
low pii_flow — User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration. Same-origin destination — not external exfiltration. 2 locations
low env_fs — Filesystem access. 2 locations
first-party (npm): packages/agent-runtime
npm first-partyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
readFileSync(path.join(TEST_DIR, 'fixtures/goal-loop.graph.json'), 'utf8'),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/agent-tracing
npm first-partyexpand_more 20 low-confidence finding(s)
low env_fs — Filesystem access. 16 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
if (process.env.TRACING_BASE_URL) return process.env.TRACING_BASE_URL;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/app-config
npm first-partyexpand_more 12 low-confidence finding(s)
low env_fs — Environment-variable access. 12 locations
first-party (npm): packages/builtin-tool-cloud-sandbox
npm first-partyexpand_more 3 low-confidence finding(s)
const response = await fetch(pluginState.downloadUrl);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
low env_fs — Filesystem access. 2 locations
first-party (npm): packages/builtin-tool-creds
npm first-partyexpand_more 1 low-confidence finding(s)
const appUrl = (process.env.APP_URL || OFFICIAL_URL).replace(/\/+$/, '');
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/builtin-tool-local-system
npm first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
first-party (npm): packages/builtin-tool-skills
npm first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
first-party (npm): packages/chat-adapter-feishu
npm first-partyexpand_more 4 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
first-party (npm): packages/chat-adapter-imessage
npm first-partyexpand_more 1 low-confidence finding(s)
return await fetch(url, { ...init, signal });
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/chat-adapter-line
npm first-partyexpand_more 3 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
first-party (npm): packages/chat-adapter-qq
npm first-partyexpand_more 4 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
const response = await fetch(AUTH_URL, {
body: JSON.stringify({
appId: this.appId,
clientSecret: this.clientSecret,
}),
headers: { 'Content-Type': 'application/json' },
method: 'POST',
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/chat-adapter-wechat
npm first-partyexpand_more 11 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 11 locations
first-party (npm): packages/connector-data
npm first-partyexpand_more 1 low-confidence finding(s)
response = await transport.request({ operation, query, variables });
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/database
npm first-partyexpand_more 35 low-confidence finding(s)
low env_fs — Environment-variable access. 26 locations
low env_fs — Filesystem access. 8 locations
const res = await fetch('https://api.anthropic.com/api/oauth/usage', {
headers: {
'Authorization': `Bearer ${readToken()}`,
'User-Agent': 'claude-cli/2.1.198 (external, cli)',
'anthropic-beta': 'oauth-2025-04-20',
},
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/device-control
npm first-partyexpand_more 36 low-confidence finding(s)
low env_fs — Filesystem access. 36 locations
first-party (npm): packages/device-gateway-client
npm first-partyexpand_more 1 low-confidence finding(s)
return fetch(`${this.gatewayUrl}${path}`, {
body: JSON.stringify(body),
headers: {
'Authorization': `Bearer ${this.serviceToken}`,
'Content-Type': 'application/json',
},
method: 'POST',
...(options?.timeout ? { signal: AbortSignal.timeout(options.timeout) } : {}),
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/device-sandbox
npm first-partyexpand_more 3 low-confidence finding(s)
first-party (npm): packages/edge-config
npm first-partyexpand_more 1 low-confidence finding(s)
return this.client.get<EdgeConfigData[K]>(key);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/electron-server-ipc
npm first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
first-party (npm): packages/env
npm first-partyexpand_more 431 low-confidence finding(s)
low env_fs — Environment-variable access. 431 locations
first-party (npm): packages/eval-dataset-parser
npm first-partyexpand_more 6 low-confidence finding(s)
low env_fs — Filesystem access. 6 locations
first-party (npm): packages/file-loaders
npm first-partyexpand_more 7 low-confidence finding(s)
low env_fs — Filesystem access. 7 locations
first-party (npm): packages/llm-generation-tracing
npm first-partyexpand_more 8 low-confidence finding(s)
low env_fs — Filesystem access. 8 locations
first-party (npm): packages/local-file-shell
npm first-partyexpand_more 79 low-confidence finding(s)
low env_fs — Filesystem access. 79 locations
first-party (npm): packages/memory-user-memory
npm first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
const res = await fetch(new URL(path, baseUrl).toString(), {
body: JSON.stringify(body),
headers: {
'Content-Type': 'application/json',
...webhookHeaders,
},
method: 'POST',
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
const raw = readFileSync(absPath, 'utf8');
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/model-bank
npm first-partyexpand_more 1 low-confidence finding(s)
const packageJson = JSON.parse(readFileSync(packageJsonPath, 'utf8')) as {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (npm): packages/observability-otel
npm first-partyexpand_more 11 low-confidence finding(s)
low env_fs — Environment-variable access. 11 locations
first-party (npm): packages/openapi
npm first-partyexpand_more 5 low-confidence finding(s)
const bin = fs.readFileSync((f as any).filepath);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Environment-variable access. 4 locations
first-party (npm): packages/python-interpreter
npm first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Filesystem access. 4 locations
const buffer = await fetch(url, { cache: 'force-cache' }).then((res) => res.arrayBuffer());
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): packages/ssrf-safe-fetch
npm first-partyexpand_more 12 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
low env_fs — Environment-variable access. 10 locations
first-party (npm): packages/tool-runtime
npm first-partyexpand_more 3 low-confidence finding(s)
first-party (npm): packages/trpc
npm first-partyexpand_more 5 low-confidence finding(s)
const response = await fetch(input, { ...init, credentials: 'include' });
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
low env_fs — Environment-variable access. 4 locations
first-party (npm): packages/utils
npm first-partyexpand_more 8 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
low env_fs — Environment-variable access. 3 locations
Skipped dependencies
Production
- first-party (npm): apps/server prod — scan budget exceeded
- @ant-design/icons prod — scan budget exceeded
- @ant-design/pro-components prod — scan budget exceeded
- @anthropic-ai/sdk prod — scan budget exceeded
- @atlaskit/pragmatic-drag-and-drop prod — scan budget exceeded
- @atlaskit/pragmatic-drag-and-drop-hitbox prod — scan budget exceeded
- @aws-sdk/client-bedrock-runtime prod — scan budget exceeded
- @aws-sdk/client-s3 prod — scan budget exceeded
- @aws-sdk/s3-request-presigner prod — scan budget exceeded
- @azure-rest/ai-inference prod — scan budget exceeded
- @azure/core-auth prod — scan budget exceeded
- @better-auth/expo prod — scan budget exceeded
- @better-auth/passkey prod — scan budget exceeded
- @cfworker/json-schema prod — scan budget exceeded
- @chat-adapter/discord prod — scan budget exceeded
- @chat-adapter/slack prod — scan budget exceeded
- @chat-adapter/state-ioredis prod — scan budget exceeded
- @chat-adapter/telegram prod — scan budget exceeded
- @codesandbox/sandpack-react prod — scan budget exceeded
- @composio/core prod — scan budget exceeded
- @discordjs/rest prod — scan budget exceeded
- @dnd-kit/core prod — scan budget exceeded
- @dnd-kit/sortable prod — scan budget exceeded
- @dnd-kit/utilities prod — scan budget exceeded
- @emoji-mart/data prod — scan budget exceeded
- @emoji-mart/react prod — scan budget exceeded
- @emotion/react prod — scan budget exceeded
- @fal-ai/client prod — scan budget exceeded
- @floating-ui/react prod — scan budget exceeded
- @formkit/auto-animate prod — scan budget exceeded
- @google/genai prod — scan budget exceeded
- @henrygd/queue prod — scan budget exceeded
- @huggingface/inference prod — scan budget exceeded
- @icons-pack/react-simple-icons prod — scan budget exceeded
- @khmyznikov/pwa-install prod — scan budget exceeded
- @larksuiteoapi/node-sdk prod — scan budget exceeded
- @lexical/utils prod — scan budget exceeded
- @lobehub/analytics prod — scan budget exceeded
- @lobehub/charts prod — scan budget exceeded
- @lobehub/editor prod — scan budget exceeded
- @lobehub/icons prod — scan budget exceeded
- @lobehub/market-sdk prod — scan budget exceeded
- @lobehub/tts prod — scan budget exceeded
- @lobehub/ui prod — scan budget exceeded
- @modelcontextprotocol/sdk prod — scan budget exceeded
- @napi-rs/canvas prod — scan budget exceeded
- @neondatabase/serverless prod — scan budget exceeded
- @next/third-parties prod — scan budget exceeded
- @opentelemetry/auto-instrumentations-node prod — scan budget exceeded
- @opentelemetry/exporter-jaeger prod — scan budget exceeded
- @opentelemetry/resources prod — scan budget exceeded
- @opentelemetry/sdk-metrics prod — scan budget exceeded
- @opentelemetry/winston-transport prod — scan budget exceeded
- @pierre/trees prod — scan budget exceeded
- @react-pdf/renderer prod — scan budget exceeded
- @react-three/drei prod — scan budget exceeded
- @react-three/fiber prod — scan budget exceeded
- @saintno/comfyui-sdk prod — scan budget exceeded
- @t3-oss/env-core prod — scan budget exceeded
- @t3-oss/env-nextjs prod — scan budget exceeded
- @tanstack/react-query prod — scan budget exceeded
- @trpc/client prod — scan budget exceeded
- @trpc/next prod — scan budget exceeded
- @trpc/react-query prod — scan budget exceeded
- @trpc/server prod — scan budget exceeded
- @upstash/qstash prod — scan budget exceeded
- @upstash/workflow prod — scan budget exceeded
- @vercel/analytics prod — scan budget exceeded
- @vercel/edge-config prod — scan budget exceeded
- @vercel/functions prod — scan budget exceeded
- @vercel/speed-insights prod — scan budget exceeded
- @virtuoso.dev/masonry prod — scan budget exceeded
- @xterm/addon-fit prod — scan budget exceeded
- @xterm/addon-webgl prod — scan budget exceeded
- @xterm/xterm prod — scan budget exceeded
- @zumer/snapdom prod — scan budget exceeded
- ahooks prod — scan budget exceeded
- antd prod — scan budget exceeded
- antd-style prod — scan budget exceeded
- async-retry prod — scan budget exceeded
- bcryptjs prod — scan budget exceeded
- better-auth prod — scan budget exceeded
- brotli-wasm prod — scan budget exceeded
- buffer.js prod — scan budget exceeded
- chat prod — scan budget exceeded
- chroma-js prod — scan budget exceeded
- class-variance-authority prod — scan budget exceeded
- cmdk prod — scan budget exceeded
- cookie prod — scan budget exceeded
- countries-and-timezones prod — scan budget exceeded
- d3-dsv prod — scan budget exceeded
- dayjs prod — scan budget exceeded
- debug prod — scan budget exceeded
- dexie prod — scan budget exceeded
- diff prod — scan budget exceeded
- discord-api-types prod — scan budget exceeded
- drizzle-orm prod — scan budget exceeded
- drizzle-zod prod — scan budget exceeded
- epub2 prod — scan budget exceeded
- es-toolkit prod — scan budget exceeded
- expo-server-sdk prod — scan budget exceeded
- fast-deep-equal prod — scan budget exceeded
- fflate prod — scan budget exceeded
- ffmpeg-static prod — scan budget exceeded
- file-type prod — scan budget exceeded
- fuse.js prod — scan budget exceeded
- gray-matter prod — scan budget exceeded
- hono prod — scan budget exceeded
- html-to-text prod — scan budget exceeded
- i18next prod — scan budget exceeded
- i18next-browser-languagedetector prod — scan budget exceeded
- i18next-resources-to-backend prod — scan budget exceeded
- immer prod — scan budget exceeded
- ioredis prod — scan budget exceeded
- jose prod — scan budget exceeded
- js-sha256 prod — scan budget exceeded
- jsondiffpatch prod — scan budget exceeded
- jsonl-parse-stringify prod — scan budget exceeded
- langfuse prod — scan budget exceeded
- langfuse-core prod — scan budget exceeded
- lexical prod — scan budget exceeded
- lucide-react prod — scan budget exceeded
- mammoth prod — scan budget exceeded
- marked prod — scan budget exceeded
- mdast-util-to-markdown prod — scan budget exceeded
- motion prod — scan budget exceeded
- nanoid prod — scan budget exceeded
- next prod — scan budget exceeded
- next-mdx-remote prod — scan budget exceeded
- next-themes prod — scan budget exceeded
- nextjs-toploader prod — scan budget exceeded
- node-machine-id prod — scan budget exceeded
- nodemailer prod — scan budget exceeded
- numeral prod — scan budget exceeded
- nuqs prod — scan budget exceeded
- octokit prod — scan budget exceeded
- officeparser prod — scan budget exceeded
- ogl prod — scan budget exceeded
- oidc-provider prod — scan budget exceeded
- ollama prod — scan budget exceeded
- openai prod — scan budget exceeded
- openapi-fetch prod — scan budget exceeded
- partial-json prod — scan budget exceeded
- path-browserify-esm prod — scan budget exceeded
- pathe prod — scan budget exceeded
- pdf-parse prod — scan budget exceeded
- pdfjs-dist prod — scan budget exceeded
- pdfkit prod — scan budget exceeded
- pg prod — scan budget exceeded
- pinyin-pro prod — scan budget exceeded
- plaiceholder prod — scan budget exceeded
- polished prod — scan budget exceeded
- posthog-js prod — scan budget exceeded
- pure-rand prod — scan budget exceeded
- pwa-install-handler prod — scan budget exceeded
- query-string prod — scan budget exceeded
- random-words prod — scan budget exceeded
- rc-util prod — scan budget exceeded
- react prod — scan budget exceeded
- react-confetti prod — scan budget exceeded
- react-dom prod — scan budget exceeded
- react-fast-marquee prod — scan budget exceeded
- react-hotkeys-hook prod — scan budget exceeded
- react-i18next prod — scan budget exceeded
- react-lazy-load prod — scan budget exceeded
- react-markdown prod — scan budget exceeded
- react-pdf prod — scan budget exceeded
- react-responsive prod — scan budget exceeded
- react-rnd prod — scan budget exceeded
- react-router prod — scan budget exceeded
- react-scan prod — scan budget exceeded
- react-virtuoso prod — scan budget exceeded
- react-wrap-balancer prod — scan budget exceeded
- remark prod — scan budget exceeded
- remark-gfm prod — scan budget exceeded
- remark-html prod — scan budget exceeded
- remove-markdown prod — scan budget exceeded
- resend prod — scan budget exceeded
- resolve-accept-language prod — scan budget exceeded
- rtl-detect prod — scan budget exceeded
- semver prod — scan budget exceeded
- sharp prod — scan budget exceeded
- shiki prod — scan budget exceeded
- stripe prod — scan budget exceeded
- superjson prod — scan budget exceeded
- svix prod — scan budget exceeded
- swr prod — scan budget exceeded
- three prod — scan budget exceeded
- tokenx prod — scan budget exceeded
- ts-md5 prod — scan budget exceeded
- ua-parser-js prod — scan budget exceeded
- undici prod — scan budget exceeded
- unist-builder prod — scan budget exceeded
- url-join prod — scan budget exceeded
- use-merge-value prod — scan budget exceeded
- uuid prod — scan budget exceeded
- virtua prod — scan budget exceeded
- word-extractor prod — scan budget exceeded
- ws prod — scan budget exceeded
- xast-util-to-xml prod — scan budget exceeded
- xastscript prod — scan budget exceeded