Close Open Privacy Scan

bolt Snapshot: commit 25f1e3c
science engine v1.23
schedule 2026-07-27T03:15:56.172231+00:00

verified_user Application data leak confirmed

High-confidence data exfiltration identified in application code.

smart_toy MCP server detected: @ai-sdk/anthropic, @ai-sdk/openai, @modelcontextprotocol/sdk, ai — detected in dependencies, not a safety judgment.
Incomplete scan — only 88/191 dependencies were analyzed. Treat the score as provisional.

App Privacy Score

0 /100
High privacy risk — application leak confirmed

High risk · 1064 finding(s)

Based on: 9 first-party package(s) · 88/191 deps analyzed

Dependency score: 0 (High risk)

bar_chart Score Breakdown

pii_flow −60
telemetry −25
egress −15
env_fs −3

list Scan Summary

17 high 107 medium 940 low
First-party packages: 5
Dependency packages: 24
Ecosystem: npm

swap_horiz Confirmed data exfiltration in application code

External domains: access.line.meaccount.box.comaccountname.blob.core.windows.netaccounts.faceit.comaccounts.google.comaccounts.spotify.comaccounts.zoho.comall-http-intake.logs.datad0g.comapi.anthropic.comapi.atlassian.comapi.box.comapi.coinbase.comapi.dropboxapi.comapi.faceit.comapi.foursquare.comapi.freshbooks.comapi.github.comapi.hubapi.comapi.instagram.comapi.intra.42.frapi.linkedin.comapi.medium.comapi.netlify.comapi.openai.comapi.pinterest.comapi.pipedrive.comapi.reference.langfuse.comapi.spotify.comapi.todoist.comapi.trakt.tvapi.twitter.comapi.usepylon.comapi.vk.comapi.workos.comapi.zoom.usapp.circleci.comapp.exampleapp.hubspot.comapp.netlify.comapp.posthog.comappleid.apple.comauth.atlassian.comauth.freshbooks.comauthjs.devavatars.yandex.netbedrock-agent-runtime.us-west-2.amazonaws.combedrock-runtime.us-east-1.amazonaws.combitbucket.orgboosty.tobrowser-intake-ap1-datadoghq.combrowser-intake-ap2-datadoghq.combrowser-intake-uk1-datadoghq.comcal.comcdn.discordapp.comci.appveyor.comclickhouse.comcloud.google.comcloud.langfuse.comcommons.wikimedia.orgdate-fns.orgdiscord.comdocs.aws.amazon.comdocs.github.comdocs.langfuse.comdtdg.coen.wikipedia.orgeu.posthog.comexample.okta.comfoursquare.comgithub.acme.comgithub.comgitlab.comgraph.facebook.comgraph.instagram.comgraph.microsoft.comhipaa.cloud.langfuse.comhttp-intake.logsid.twitch.tvimage.eveonline.comimg.shields.iojp.cloud.langfuse.comjson-schema.orgkapi.kakao.comkauth.kakao.comlangfuse.comlangfuse.locallogin.eveonline.comlogin.mailchimp.comlogin.microsoftonline.comlogin.salesforce.comlogin.yandex.rulu.mamedium.commeta.wikimedia.orgmixpanel.comnext-auth.js.orgnid.naver.comnpms.iooauth.mail.ruoauth.pipedrive.comoauth.reddit.comoauth.vk.comoauth.yandex.ruopenapi.naver.comopencollective.comosu.ppy.shpatreon.complatform.openai.complay.min.ioposthog.compublic-api.wordpress.compublic-trace-http-intake.logs.datad0g.compublic-trace-http-intake.logs.datadoghq.compublic-trace-http-intake.logs.datadoghq.euraw.githubusercontent.comsentry.ioslack.comstaging.langfuse.comstatic.langfuse.comstatic.modelcontextprotocol.iostatus.langfuse.comtanstack.comtodoist.comtools.ietf.orgtrace.browser-intake-us3-datadoghq.comtrace.browser-intake-us5-datadoghq.comtrakt.tvtrpc.iotwitter.comus.cloud.langfuse.comus.i.posthog.comus.posthog.comwww.battlenet.com.cnwww.bungie.netwww.coinbase.comwww.datadoghq.comwww.dropbox.comwww.eclipse.orgwww.facebook.comwww.googleapis.comwww.linkedin.comwww.patreon.comwww.pinterest.comwww.reddit.comwww.strava.comwww.w3.orgx.comx.localyour-instance.openai.azure.comyour-service.comzoom.us

high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:107
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:137
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:144
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/features/auth-credentials/server/signupApiHandler.ts:95
  2. 2sinkrepo/web/src/features/auth-credentials/server/signupApiHandler.ts:116
high first-party (npm): web A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcerepo/web/src/features/auth-credentials/server/signupApiHandler.ts:96
  2. 2sinkrepo/web/src/features/auth-credentials/server/signupApiHandler.ts:118
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/pages/api/auth/signup-verify.ts:12
  2. 2sinkrepo/web/src/pages/api/auth/signup-verify.ts:96
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/pages/auth/enterprise-sso-required.tsx:84
  2. 2sinkrepo/web/src/pages/auth/enterprise-sso-required.tsx:92
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/pages/auth/sign-in.tsx:663
  2. 2sinkrepo/web/src/pages/auth/sign-in.tsx:677
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/pages/auth/sign-up.tsx:134
  2. 2sinkrepo/web/src/pages/auth/sign-up.tsx:149
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/pages/auth/sign-up.tsx:355
  2. 2sinkrepo/web/src/pages/auth/sign-up.tsx:350
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/server/adminAccessWebhook.ts:47
  2. 2sinkrepo/web/src/server/adminAccessWebhook.ts:57
high first-party (npm): web User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
  1. 1sourcerepo/web/src/server/auth.ts:1123
  2. 2sinkrepo/web/src/server/auth.ts:1119
medium first-party (npm): web Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:250
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247
medium first-party (npm): web Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:347
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337
medium first-party (npm): web Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
  1. 1sourcerepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:388
  2. 2sinkrepo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378
hub Dependency data flows (14)
high next-auth dependency A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcepkgs/npm/[email protected]/core/lib/oauth/callback.js:83
  2. 2sinkpkgs/npm/[email protected]/core/lib/oauth/callback.js:86
high next-auth dependency A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcepkgs/npm/[email protected]/core/lib/oauth/callback.js:83
  2. 2sinkpkgs/npm/[email protected]/core/lib/oauth/callback.js:103
high next-auth dependency A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcepkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:87
  2. 2sinkpkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:91
high next-auth dependency A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcepkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:87
  2. 2sinkpkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:111
high @ai-sdk/amazon-bedrock dependency A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
  1. 1sourcepkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:76
  2. 2sinkpkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:87
medium next-auth dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/providers/trakt.js:23
  2. 2sinkpkgs/npm/[email protected]/providers/trakt.js:22
medium next-auth dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/src/providers/trakt.ts:35
  2. 2sinkpkgs/npm/[email protected]/src/providers/trakt.ts:34
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:401
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:453
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:522
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:543
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:583
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:595
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:711
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:723
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1222
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1244
medium posthog-js dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1284
  2. 2sinkpkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1295
medium @ai-sdk/amazon-bedrock dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:76
  2. 2sinkpkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:90

</> First-Party Code

first-party (npm): web

npm first-party
high pii_flow production #cb739457d5e20f27 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:107 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247
      const { ok } = await this.post({
        url: this.config.userUrl,
        payload: { isLangfuse: true, ...parsed.data },
        context: { event: "upsertUser", userId: parsed.data.userId },
        expectJsonResponse: false,
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #aed8886e45ad1270 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:137 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337
        const { ok } = await this.post({
          url: this.config.orgUrl,
          payload: {
            isLangfuse: true,
            type: "setUserRole" as const,
            ...parsed.data,
          },
          context: {
            event: "setUserRole",
            orgId: parsed.data.orgId,
            userId: parsed.data.userId,
          },
          expectJsonResponse: false,
        });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #eb8036057343f621 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:144 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378
        const { ok } = await this.post({
          url: this.config.orgUrl,
          payload: {
            isLangfuse: true,
            type: "removeUser" as const,
            ...parsed.data,
          },
          context: {
            event: "removeUser",
            orgId: parsed.data.orgId,
            userId: parsed.data.userId,
          },
          expectJsonResponse: false,
        });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #71d4f95d32d56936 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/features/auth-credentials/server/signupApiHandler.ts:116 · flow /tmp/closeopen-vjq1w0us/repo/web/src/features/auth-credentials/server/signupApiHandler.ts:95 → /tmp/closeopen-vjq1w0us/repo/web/src/features/auth-credentials/server/signupApiHandler.ts:116
    await fetch(env.LANGFUSE_NEW_USER_SIGNUP_WEBHOOK, {
      method: "POST",
      body: JSON.stringify({
        name: body.name,
        email: body.email,
        referralSource: body.referralSource,
        cloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
        userId: userId,
      }),
      headers: {
        "Content-Type": "application/json",
      },
    });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #fae908e9193cd54f A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
repo/web/src/features/auth-credentials/server/signupApiHandler.ts:118 · flow /tmp/closeopen-vjq1w0us/repo/web/src/features/auth-credentials/server/signupApiHandler.ts:96 → /tmp/closeopen-vjq1w0us/repo/web/src/features/auth-credentials/server/signupApiHandler.ts:118
      body: JSON.stringify({
        name: body.name,
        email: body.email,
        referralSource: body.referralSource,
        cloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
        userId: userId,
      }),

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #35352755c78ca6e1 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/pages/api/auth/signup-verify.ts:96 · flow /tmp/closeopen-vjq1w0us/repo/web/src/pages/api/auth/signup-verify.ts:12 → /tmp/closeopen-vjq1w0us/repo/web/src/pages/api/auth/signup-verify.ts:96
      await fetch(env.LANGFUSE_NEW_USER_SIGNUP_WEBHOOK, {
        method: "POST",
        body: JSON.stringify({
          name,
          email: normalizedEmail,
          cloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
          userId: newUser.id,
        }),
        headers: {
          "Content-Type": "application/json",
        },
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #4a9340fe22832107 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/pages/auth/enterprise-sso-required.tsx:92 · flow /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/enterprise-sso-required.tsx:84 → /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/enterprise-sso-required.tsx:92
      const response = await fetch(
        `${env.NEXT_PUBLIC_BASE_PATH ?? ""}/api/auth/check-sso`,
        {
          method: "POST",
          headers: { "Content-Type": "application/json" },
          body: JSON.stringify({ domain }),
        },
      );

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #3ea0650888a84884 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/pages/auth/sign-in.tsx:677 · flow /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-in.tsx:663 → /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-in.tsx:677
      const res = await fetch(
        `${env.NEXT_PUBLIC_BASE_PATH ?? ""}/api/auth/check-sso`,
        {
          method: "POST",
          headers: { "Content-Type": "application/json" },
          body: JSON.stringify({ domain }),
        },
      );

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #1b38c251ad2603bc User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/pages/auth/sign-up.tsx:149 · flow /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-up.tsx:134 → /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-up.tsx:149
      const res = await fetch(
        `${env.NEXT_PUBLIC_BASE_PATH ?? ""}/api/auth/check-sso`,
        {
          method: "POST",
          headers: { "Content-Type": "application/json" },
          body: JSON.stringify({ domain }),
        },
      );

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #db6d8768dc3a1aee User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/pages/auth/sign-up.tsx:350 · flow /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-up.tsx:355 → /tmp/closeopen-vjq1w0us/repo/web/src/pages/auth/sign-up.tsx:350
      const res = await fetch(
        `${env.NEXT_PUBLIC_BASE_PATH ?? ""}/api/auth/signup-verify`,
        {
          method: "POST",
          headers: { "Content-Type": "application/json" },
          body: JSON.stringify({ email: values.email, name: values.name }),
        },
      );

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #7bf56cbaf091762e User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/server/adminAccessWebhook.ts:57 · flow /tmp/closeopen-vjq1w0us/repo/web/src/server/adminAccessWebhook.ts:47 → /tmp/closeopen-vjq1w0us/repo/web/src/server/adminAccessWebhook.ts:57
    const response = await fetch(env.LANGFUSE_ADMIN_ACCESS_WEBHOOK, {
      method: "POST",
      body: JSON.stringify(payload),
      headers: {
        "Content-Type": "application/json",
      },
    });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow production #9480f8c59a9711b6 User/PII-bearing data read from the environment or filesystem flows to an external network call. This is potential data exfiltration.
repo/web/src/server/auth.ts:1119 · flow /tmp/closeopen-vjq1w0us/repo/web/src/server/auth.ts:1123 → /tmp/closeopen-vjq1w0us/repo/web/src/server/auth.ts:1119
          await fetch(env.LANGFUSE_NEW_USER_SIGNUP_WEBHOOK, {
            method: "POST",
            body: JSON.stringify({
              name: user.name,
              email: user.email,
              cloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
              userId: user.id,
              // referralSource: ...
            }),
            headers: {
              "Content-Type": "application/json",
            },
          });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium telemetry production #b9437a622575e5f5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/instrumentation-client.ts:1
import * as Sentry from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry test-only Excluded from app score #41a7ec5b862408f8 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/next.config.mjs:6
import { withSentryConfig } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6367c383c0ee1d7f capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/components/error-page.tsx:7
import { captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow production #4d85cde205db0087 Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:250 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:247
      const { ok } = await this.post({
        url: this.config.userUrl,
        payload: { isLangfuse: true, ...parsed.data },
        context: { event: "upsertUser", userId: parsed.data.userId },
        expectJsonResponse: false,
      });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #ba72be26d28079e8 Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:347 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:337
        const { ok } = await this.post({
          url: this.config.orgUrl,
          payload: {
            isLangfuse: true,
            type: "setUserRole" as const,
            ...parsed.data,
          },
          context: {
            event: "setUserRole",
            orgId: parsed.data.orgId,
            userId: parsed.data.userId,
          },
          expectJsonResponse: false,
        });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow production #7d77edc46fddb1b3 Credentials parsed from the request URL are applied as authorization on the same outbound HTTP request. This is intentional URL authentication, not unexpected data exfiltration.
repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378 · flow /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:388 → /tmp/closeopen-vjq1w0us/repo/web/src/ee/features/sfdc-sync/server/sfdcService.ts:378
        const { ok } = await this.post({
          url: this.config.orgUrl,
          payload: {
            isLangfuse: true,
            type: "removeUser" as const,
            ...parsed.data,
          },
          context: {
            event: "removeUser",
            orgId: parsed.data.orgId,
            userId: parsed.data.userId,
          },
          expectJsonResponse: false,
        });

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium telemetry production #3c66f8ac20ede4ad capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/auth/lib/createProjectMembershipsOnSignup.ts:287
        posthog.capture({
          distinctId: user.id,
          event: "cloud_signup_complete",
          properties: {
            cloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
            hasDemoAccess: demoProject !== undefined,
            hasDefaultOrg: defaultOrgs.length > 0,
            hasDefaultProject: defaultProjects.length > 0,
          },
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #efad511f87273623 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/auth/lib/createProjectMembershipsOnSignup.ts:297
        await posthog.shutdown();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #ac4d58132f09a369 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/auth/lib/signOut.ts:2
import posthog from "posthog-js";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #78ab7d19d7132404 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/auth/lib/signOut.ts:18
    posthog.reset();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6297d75c16300971 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/events/hooks/useV4Beta.ts:4
import posthog from "posthog-js";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #c181aa697a4a6ec0 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/events/hooks/useV4Beta.ts:35
            posthog.setPersonProperties({
              [V4_BETA_ENABLED_POSTHOG_PROPERTY]: v4BetaEnabled,
            });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #0743896bf6438879 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/events/hooks/useV4Beta.ts:38
            posthog.register({
              [V4_BETA_ENABLED_POSTHOG_PROPERTY]: v4BetaEnabled,
            });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #0fe4ed2a6ce921e6 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/posthog-analytics/ServerPosthog.ts:2
import { PostHog } from "posthog-node";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #cf6f96f3cf9602ca capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/posthog-analytics/usePostHogClientCapture.ts:1
import { type CaptureResult, type CaptureOptions } from "posthog-js";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #daed717689ccace0 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/posthog-analytics/usePostHogClientCapture.ts:352
      return posthog.capture(eventName, properties, options);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #cda4312d7179ce0b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/telemetry/index.ts:252
    posthog.capture({
      distinctId: "docker:" + clientId,
      event: "telemetry",
      properties: {
        langfuseVersion: VERSION,
        userDomains: domains,
        totalProjects: totalProjects,
        traces: countTraces,
        scores: countScores,
        observations: countObservations,
        datasets: countDatasets,
        datasetItems: countDatasetItems,
        datasetRuns: countDatasetRuns,
        datasetRunItems: countDatasetRunItems,
        startTimeframe: startTimeframe?.toISOString(),
        endTimeframe: endTimeframe.toISOString(),
        eeLicenseKey: env.LANGFUSE_EE_LICENSE_KEY,
        langfuseCloudRegion: env.NEXT_PUBLIC_LANGFUSE_CLOUD_REGION,
        $set: {
          environment: process.env.NODE_ENV,
          userDomains: domains,
          docker: true,
          langfuseVersion: VERSION,
        },
      },
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #0ec30fdf979c9618 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/features/telemetry/index.ts:279
    await posthog.shutdown();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #f79df9279ef7accf capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/hooks/parserWorkerError.clienttest.ts:2
import { captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #dd8a8a4d8ee1f2e7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/hooks/parserWorkerError.ts:1
import { captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #ccc8a39a42cd51fa capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:9
import { setUser } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #b0178bbc2145f200 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:24
import posthog from "posthog-js";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #444f5a8972a25c74 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:96
  posthog.init(process.env.NEXT_PUBLIC_POSTHOG_KEY, {
    api_host: process.env.NEXT_PUBLIC_POSTHOG_HOST || "https://eu.posthog.com",
    ui_host: "https://eu.posthog.com",
    // Enable debug mode in development
    loaded: (posthog) => {
      if (process.env.NODE_ENV === "development") posthog.debug();
    },
    session_recording: {
      maskCapturedNetworkRequestFn(request) {
        request.requestBody = request.requestBody ? "REDACTED" : undefined;
        request.responseBody = request.responseBody ? "REDACTED" : undefined;
        return request;
      },
    },
    autocapture: false,
    enable_heatmaps: false,
    persistence: "cookie",
  });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #e0b38cc8b408d0c0 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:101
      if (process.env.NODE_ENV === "development") posthog.debug();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6329665e4b122cc8 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:128
        posthog.capture("$pageview");

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #3a995a50a51f0e09 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:211
        posthog.identify(sessionUser.id ?? undefined, {
          environment: process.env.NODE_ENV,
          email: sessionUser.email ?? undefined,
          name: sessionUser.name ?? undefined,
          featureFlags: sessionUser.featureFlags ?? undefined,
          projects:
            sessionUser.organizations.flatMap((org) =>
              org.projects.map((project) => ({
                ...project,
                organization: org,
              })),
            ) ?? undefined,
          LANGFUSE_CLOUD_REGION: region,
          [V4_BETA_ENABLED_POSTHOG_PROPERTY]:
            sessionUser.v4BetaEnabled ?? false,
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #918cedfa98e66859 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:227
        posthog.register({
          [V4_BETA_ENABLED_POSTHOG_PROPERTY]:
            sessionUser.v4BetaEnabled ?? false,
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #d37543a17e2bd8d7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_app.tsx:240
      posthog.unregister(V4_BETA_ENABLED_POSTHOG_PROPERTY);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #0b86e3cc55c6423e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/_error.tsx:1
import {
  captureUnderscoreErrorException,
  isEnabled as isSentryEnabled,
} from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #f9cee43a6908527a capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/pages/auth/sign-in.tsx:41
import { captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #231931074e83d9bc capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/utils/api.ts:8
import { addBreadcrumb, captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a35dd0a78c0bf809 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/utils/reportError.ts:1
import { addBreadcrumb, captureException } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #c95021dee35d230b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/utils/sentryFilters.clienttest.ts:1
import { type ErrorEvent } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #2049d11177f69c54 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/web/src/utils/sentryFilters.ts:1
import { type ErrorEvent } from "@sentry/nextjs";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 436 low-confidence finding(s)
low env_fs Filesystem access. 12 locations
low env_fs Environment-variable access. 386 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 34 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 4 locations

first-party (npm): worker

npm first-party
medium telemetry test-only Excluded from app score #9d5c492d7ed9c4c4 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/__tests__/posthogNodeDelivery.test.ts:3
import { PostHog } from "posthog-node";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #bdcbccdbc458e942 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:36
  const hadEvents = mixpanel.getBatchSize() > 0;

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #22fa91da074217e2 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:37
  await mixpanel.flush();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #e2a43e297d5e7897 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:76
    mixpanel.addEvent(event);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #941c2390ddc050d3 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:111
    mixpanel.addEvent(event);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a5933dc798905ba9 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:150
    mixpanel.addEvent(event);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a3b187c35c6ddb3c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:184
    mixpanel.addEvent(event);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #ee0d3e11a8630a9e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/mixpanel/handleMixpanelIntegrationProjectJob.ts:303
      bytes: mixpanel.getSerializedBytes(),

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #892c100948ad717e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:21
import { PostHog } from "posthog-node";

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #9bbd0775b3c94e9c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:66
  await posthog.flush();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #76ce63eac7a7fc6d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:116
    posthog.capture(transform(value, config.projectId));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #a67d505aa94fbd60 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:336
      posthog.on("error", (error) => {
        logger.error(
          `[POSTHOG] Error sending data to PostHog for project ${projectId}: ${error}`,
        );
        executionConfig.sendError =
          error instanceof Error ? error : new Error(String(error));
      });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #8d08ace942038cc8 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:365
        await posthog.shutdown();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry production #6cc3891900f467cf capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
repo/worker/src/features/posthog/handlePostHogIntegrationProjectJob.ts:375
    await posthog.shutdown();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 152 low-confidence finding(s)
low env_fs Environment-variable access. 108 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
low env_fs Filesystem access. 17 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 21 locations
low pii_flow test-only Excluded from app score #a8729c459d8207c9 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration. Non-production path — not application runtime.
repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:265 · flow /tmp/closeopen-vjq1w0us/repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:57 → /tmp/closeopen-vjq1w0us/repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:265
      headers: {
        "Content-Type": "application/json",
        Authorization: `Bearer ${ADMIN_API_KEY}`,
      },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

low pii_flow test-only Excluded from app score #ce0ac93ffa7623b3 PII-bearing data is written to a log sink. Logged PII is a privacy concern even when it does not leave the process. Non-production path — not application runtime.
repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:282 · flow /tmp/closeopen-vjq1w0us/repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:57 → /tmp/closeopen-vjq1w0us/repo/worker/src/scripts/replayIngestionEventsV2/replay.ts:282
        console.warn(
          `  Retry ${attempt + 1}/${maxRetries} after ${resp.status} (waiting ${Math.round(delay)}ms)`,
        );

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

first-party (npm)

npm first-party
expand_more 19 low-confidence finding(s)
low env_fs Filesystem access. 12 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
low env_fs Environment-variable access. 4 locations
low egress test-only Excluded from app score #68e783e0fe1a0c09 capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
repo/scripts/in-app-agent/sync-raw-skills.mjs:97
  const response = await fetch(sourceApiUrl, {
    headers: getGitHubHeaders(),
  });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (npm): packages/shared

npm first-party
expand_more 44 low-confidence finding(s)
low env_fs Environment-variable access. 16 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
low env_fs Filesystem access. 22 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

</> Dependencies

next-auth

npm dependency
high pii_flow dependency Excluded from app score #d8fc3c5a88b19d95 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
pkgs/npm/[email protected]/core/lib/oauth/callback.js:86 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/core/lib/oauth/callback.js:83 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/core/lib/oauth/callback.js:86
      const response = await provider.token.request({
        provider,
        params,
        checks,
        client
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow dependency Excluded from app score #fda8b6de6e45e2bf A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
pkgs/npm/[email protected]/core/lib/oauth/callback.js:103 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/core/lib/oauth/callback.js:83 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/core/lib/oauth/callback.js:103
      profile = await provider.userinfo.request({
        provider,
        tokens,
        client
      });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow dependency Excluded from app score #47277764bba76337 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:91 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:87 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:91
      const response = await provider.token.request({
        provider,
        params,
        checks,
        client,
      })

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

high pii_flow dependency Excluded from app score #f577b46697890695 A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:111 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:87 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/core/lib/oauth/callback.ts:111
      profile = await provider.userinfo.request({
        provider,
        tokens,
        client,
      })

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium pii_flow dependency Excluded from app score #59986f3c67504f8a A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/providers/trakt.js:22 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/providers/trakt.js:23 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/providers/trakt.js:22
          headers: {
            Authorization: `Bearer ${context.tokens.access_token}`,
            "trakt-api-version": "2",
            "trakt-api-key": context.provider.clientId
          }

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #56b2b4f0af4ad516 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/src/providers/trakt.ts:34 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/providers/trakt.ts:35 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/src/providers/trakt.ts:34
          headers: {
            Authorization: `Bearer ${context.tokens.access_token}`,
            "trakt-api-version": "2",
            "trakt-api-key": context.provider.clientId as string,
          },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 67 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 14 locations
low env_fs Environment-variable access. 41 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 10 locations
low env_fs Filesystem access. 2 locations

@ai-sdk/amazon-bedrock

npm dependency
high pii_flow dependency Excluded from app score #2b6306aa1ec73d4f A credential read from the environment/filesystem flows to an external network call in a non-auth-header position (request body). Review what is sent.
pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:87 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:76 → /tmp/closeopen-vjq1w0us/pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:87
    return fetch(input, {
      ...init,
      body,
      headers: combinedHeaders as HeadersInit,
    });

User/PII-bearing data flows to an external sink — the classic data-exfiltration shape.

Fix: Confirm no user identifiers reach this sink; redact/hash before sending, or remove the flow.

medium pii_flow dependency Excluded from app score #e780707dd1807644 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:90 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:76 → /tmp/closeopen-vjq1w0us/pkgs/npm/@[email protected]/src/bedrock-sigv4-fetch.ts:90
      headers: combinedHeaders as HeadersInit,

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 3 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

dd-trace

npm dependency
medium telemetry dependency Excluded from app score #4282ccd3d3b95565 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/operations-taint-object.js:3
const TaintedUtils = require('@datadog/native-iast-taint-tracking')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #95223e076d83bf9b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/operations.js:4
const TaintedUtils = require('@datadog/native-iast-taint-tracking')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #2d7f9e6eb84bb747 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/rewriter.js:57
      const iastRewriter = require('@datadog/wasm-js-rewriter')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #50bb15216315069b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/rewriter.js:82
    getPrepareStackTrace = require('@datadog/wasm-js-rewriter/js/stack-trace').getPrepareStackTrace

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #da468187ca775986 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/rewriter.js:233
    cacheRewrittenSourceMap = require('@datadog/wasm-js-rewriter/js/source-map').cacheRewrittenSourceMap

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #4881119a8a267c02 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/iast/taint-tracking/taint-tracking-impl.js:4
const TaintedUtils = require('@datadog/native-iast-taint-tracking')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #fe0a47b8ea0a9831 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/appsec/waf/waf_manager.js:36
      const { DDWAF } = require('@datadog/native-appsec')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #294ef07c7df7e73c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/ci-visibility/telemetry.js:69
  ciVisibilityMetrics.distribution(name, formatMetricTags(tags)).track(measure)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #04f4c86a4ec6462f capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/config/stable.js:27
      libdatadog = require('@datadog/libdatadog')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #f1fd93677fca880a capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/crashtracking/crashtracker.js:6
const libdatadog = require('@datadog/libdatadog')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #5f4c5d8f11278e16 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/llmobs/telemetry.js:92
  llmobsMetrics.distribution('init_time', tags).track(initTimeMs)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #2cb34f0cf0273dbf capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/llmobs/telemetry.js:97
  llmobsMetrics.distribution('span.raw_size', tags).track(rawEventSize)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #3d2438b64611af3a capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/llmobs/telemetry.js:103
  llmobsMetrics.distribution('span.size', tags).track(eventSize)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #66706d425c23a0eb capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/exporter_cli.js:5
const { SourceMapper, heap, encode } = require('@datadog/pprof')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #a66ac143670b3b56 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/exporters/agent.js:46
      durationDistribution.track(perf.now() - start)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #2b792ccbe74549e3 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/exporters/agent.js:63
      sizeDistribution.track(form.size())

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #5e8c6c4db6cda477 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/profiler.js:150
              const zstdCompress = require('@datadog/libdatadog').load('datadog-js-zstd').zstd_compress

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #068e163b0818fc00 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/profiler.js:176
    const { setLogger, SourceMapper } = require('@datadog/pprof')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #e022ebefb0108d99 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/profilers/shared.js:16
  const pprof = require('@datadog/pprof')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #3a3bbc5b7d0f0b3d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/profilers/space.js:35
    this.#pprof = require('@datadog/pprof')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #d59f2522f25b8152 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/profiling/profilers/wall.js:167
    this.#pprof = require('@datadog/pprof')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #ae54654752cadb91 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/runtime_metrics/runtime_metrics.js:57
        nativeMetrics = require('@datadog/native-metrics')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #39ba4d1094b09846 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/runtime_metrics/runtime_metrics.js:119
      const handle = nativeMetrics.track(span)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #7b7befb7775747fe capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/telemetry/metrics.js:78
    return this.track(value)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #b4cfdb2b5924eeb8 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/telemetry/metrics.js:82
    return this.track(-value)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #300d4357efcd5de9 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/telemetry/metrics.js:120
    return this.track(value)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #dc1b911cb7b02ae9 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/packages/dd-trace/src/tracer_metadata.js:8
    const libdatadog = require('@datadog/libdatadog')

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 91 low-confidence finding(s)
low env_fs Environment-variable access. 16 locations
low env_fs Filesystem access. 70 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations

posthog-js

npm dependency
medium telemetry dependency Excluded from app score #85a7964e25dda74e capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/customizations/setAllPersonProfilePropertiesAsPersonPropertiesForFlags.js:17
    posthog.setPersonPropertiesForFlags(personProperties);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #0576afb615a76b1b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:22
            var replayUrl = posthog.get_session_replay_url();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #062782e7168715f1 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:23
            var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #6b407c3324209fb4 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/crisp-chat-integration.js:37
        sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
            if (!reportedSessionIds.has(sessionId)) {
                updateCrispChat();
                reportedSessionIds.add(sessionId);
            }
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #70b86bd6b8f5b38b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:22
            var replayUrl = posthog.get_session_replay_url();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #f2cd00b086ae5d8d capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:23
            var personUrl = posthog.requestRouter.endpointFor('ui', "/project/".concat(posthog.config.token, "/person/").concat(posthog.get_distinct_id()));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #9e5aae92ce7ef7d7 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/intercom-integration.js:32
        sessionIdListenerUnsubscribe = posthog.onSessionId(function (sessionId) {
            if (!reportedSessionIds.has(sessionId)) {
                updateIntercom();
                reportedSessionIds.add(sessionId);
            }
        });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #9d7364611010a0f5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/entrypoints/logs.js:341
                    if (args.length > 0 && !isCapturingLog && posthog.is_capturing()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow dependency Excluded from app score #50d70adc55b1bd44 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:453 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:401 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:453
                            headers: {
                                'X-Conversations-Token': token,
                            },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #150b02a2651f2b65 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:543 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:522 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:543
                            headers: {
                                'X-Conversations-Token': token,
                            },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #d4168035ab7d7296 A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:595 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:583 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:595
                            headers: {
                                'X-Conversations-Token': token,
                            },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #619159d7ee5a4f4b A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:723 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:711 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:723
                                    headers: {
                                        'X-Conversations-Token': token,
                                    },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #9fcb51b1997992ba A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1244 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1222 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1244
                            headers: {
                                'X-Conversations-Token': token,
                            },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium pii_flow dependency Excluded from app score #a3e551f69837de3b A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1295 · flow /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1284 → /tmp/closeopen-vjq1w0us/pkgs/npm/[email protected]/lib/src/extensions/conversations/external/index.js:1295
                            headers: {
                                'X-Conversations-Token': token,
                            },

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

medium telemetry dependency Excluded from app score #8b6a1cc84ae58480 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:17
        if (!ctx.event.userId && ctx.event.anonymousId !== posthog.get_distinct_id()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #1976af496ac4d736 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:20
            posthog.reset();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #a625aabdcf6a6c99 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:22
        if (ctx.event.userId && ctx.event.userId !== posthog.get_distinct_id()) {

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #25aba61f179ff63b capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:24
            posthog.identify(ctx.event.userId);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #652ef8d70e9b3d22 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:26
        var additionalProperties = posthog.calculateEventProperties(eventName, ctx.event.properties);

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #e565a81404b6e8f5 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/segment-integration.js:55
            posthog.register({
                distinct_id: user.id(),
                $device_id: getSegmentAnonymousId(),
            });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #1c30502e648234e2 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys.js:896
                posthog.capture(posthog_surveys_types_1.SurveyEventName.SHOWN, __assign(__assign((_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _a), (surveyLanguage && (_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _b))), { sessionRecordingUrl: (_c = posthog.get_session_replay_url) === null || _c === void 0 ? void 0 : _c.call(posthog) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #e6028a5035e23ce2 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:383
    posthog.capture(posthog_surveys_types_1.SurveyEventName.SENT, __assign(__assign(__assign(__assign(__assign((_b = {}, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_NAME] = survey.name, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ID] = survey.id, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION] = survey.current_iteration, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_ITERATION_START_DATE] = survey.current_iteration_start_date, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_SUBMISSION_ID] = surveySubmissionId, _b[posthog_surveys_types_1.SurveyEventProperties.SURVEY_COMPLETED] = isSurveyCompleted, _b), (surveyLanguage && (_c = {}, _c[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _c))), { sessionRecordingUrl: (_e = posthog.get_session_replay_url) === null || _e === void 0 ? void 0 : _e.call(posthog) }), (0, surveys_1.buildSurveyResponseProperties)(responses, survey)), properties), { $set: (_d = {},
            _d[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'responded')] = true,
            _d) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #95465dd8624c0f26 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:393
        posthog.reloadFeatureFlags();

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #c312c5b44e486683 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:414
    posthog.capture(posthog_surveys_types_1.SurveyEventName.DISMISSED, __assign(__assign(__assign({}, _buildSurveyEventProperties(survey, inProgressSurvey, posthog)), (surveyLanguage && (_a = {}, _a[posthog_surveys_types_1.SurveyEventProperties.SURVEY_LANGUAGE] = surveyLanguage, _a))), { $set: (_b = {},
            _b[(0, survey_utils_1.getSurveyInteractionProperty)(survey, 'dismissed')] = true,
            _b) }));

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #d8d47d5476837009 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/lib/src/extensions/surveys/surveys-extension-utils.js:447
    posthog.capture(posthog_surveys_types_1.SurveyEventName.ABANDONED, _buildSurveyEventProperties(survey, inProgressSurvey, posthog), {
        transport: 'sendBeacon',
    });

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

posthog-node

npm dependency
medium telemetry dependency Excluded from app score #5b0854d9f1a0305c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:69
    posthog.withContext(buildRequestContextData(posthog, req), () => next())

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #d993526e4cf2d17c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:98
    posthog.addPendingPromise(
      ErrorTracking.buildEventMessage(
        posthog.getErrorPropertiesBuilder(),
        error,
        hint,
        contextData.distinctId,
        additionalProperties
      ).then((msg) => {
        return posthog._capturePreparedEvent(msg, false)
      })
    )

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #9e88e62498168743 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:100
        posthog.getErrorPropertiesBuilder(),

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #09240f26c3a1735c capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/npm/[email protected]/src/extensions/express.ts:106
        return posthog._capturePreparedEvent(msg, false)

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

expand_more 2 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations

@ag-ui/client

npm dependency
expand_more 6 low-confidence finding(s)
low egress dependency Excluded from app score #a3aacc794b2072fd capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]__sourcemap/src/agent/http.ts:61
    this.fetch = config.fetch ?? ((url, requestInit) => fetch(url, requestInit));

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs Environment-variable access. 5 locations

@astral-sh/ruff-wasm-web

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #27e9c9779ac3d41e capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]/ruff_wasm.js:794
        module_or_path = fetch(module_or_path);

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

@aws-sdk/credential-providers

npm dependency
expand_more 2 low-confidence finding(s)

@ferrucc-io/emoji-picker

npm dependency
expand_more 27 low-confidence finding(s)
low env_fs Filesystem access. 24 locations
low egress tooling Excluded from app score unknown #48629f14d087d5e2 capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
pkgs/npm/@[email protected]__reposrc/demo/scripts/updateNpmStats.ts:9
    const response = await fetch(
      "https://api.npmjs.org/downloads/point/last-month/@ferrucc-io/emoji-picker",
    );

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs Environment-variable access. 2 locations

@hookform/resolvers

npm dependency
expand_more 3 low-confidence finding(s)
low env_fs dependency Excluded from app score #2e49d430924395ee capability detected · no path traced Environment-variable access.
pkgs/npm/@[email protected]/yup/src/yup.ts:105
      if (schemaOptions?.context && process.env.NODE_ENV === 'development') {

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Filesystem access. 2 locations

@mastra/mcp

npm dependency
expand_more 10 low-confidence finding(s)
low env_fs dependency Excluded from app score #3c231abcf3789826 capability detected · no path traced Environment-variable access.
pkgs/npm/@[email protected]__sourcemap/src/client/client.ts:136
  if (process.env.NODE_OPTIONS?.includes('dd-trace')) {

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 8 locations
low env_fs dependency Excluded from app score #fb0a787d148d7159 capability detected · no path traced Filesystem access.
pkgs/npm/@[email protected]__sourcemap/src/server/server.ts:472
        html = readFileSync(appResource.htmlPath, 'utf-8');

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

@modelcontextprotocol/sdk

npm dependency
expand_more 38 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 22 locations
low egress tooling Excluded from app score unknown #54a125702a64f195 capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
pkgs/npm/@[email protected]__reposrc/scripts/fetch-spec-types.ts:16
    const response = await fetch(url);

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs tooling Excluded from app score unknown #0d697699e5cf2a9a capability detected · no path traced Filesystem access.
pkgs/npm/@[email protected]__reposrc/scripts/fetch-spec-types.ts:77
        writeFileSync(outputPath, fullContent, 'utf-8');

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Environment-variable access. 14 locations

@paralleldrive/cuid2

npm dependency
expand_more 3 low-confidence finding(s)

@prisma/instrumentation

npm dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #e73772d231589cb0 capability detected · no path traced Environment-variable access.
pkgs/npm/@[email protected]__reposrc/src/ActiveTracingHelper.ts:21
const showAllTraces = process.env.PRISMA_SHOW_ALL_TRACES === 'true'

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

@trpc/client

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #4d71496dd9d58015 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]/src/links/wsLink/wsLink.ts:40
        const requestSubscription = client
          .request({
            op,
            transformer,
          })

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

@trpc/next

npm dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #d1bd6445112143a1 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/npm/@[email protected]/src/app-dir/links/nextHttp.ts:52
        return fetch(url, {
          ...fetchOpts,
          // cache: 'no-cache',
          next: {
            revalidate,
            tags: [cacheTag],
          },
        });

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

chroma-js

npm dependency

fastest-levenshtein

npm dependency
expand_more 3 low-confidence finding(s)

ioredis

npm dependency
expand_more 2 low-confidence finding(s)

jsonpath-plus

npm dependency
expand_more 2 low-confidence finding(s)

langfuse

npm dependency
expand_more 6 low-confidence finding(s)

nanoid

npm dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #07b0e352d03e499c capability detected · no path traced Filesystem access.
pkgs/npm/[email protected]/bin/nanoid.js:18
  let json = readFileSync(join(import.meta.dirname, '..', 'package.json'))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

Skipped dependencies

Production

  • @baselime/trpc-opentelemetry-middleware prod — dist-only: no readable source
  • @codemirror/autocomplete prod — dist-only: no readable source
  • @codemirror/language prod — dist-only: no readable source
  • @codemirror/lint prod — dist-only: no readable source
  • @codemirror/search prod — dist-only: no readable source
  • @codemirror/state prod — dist-only: no readable source
  • @langfuse/shared prod — registry 404
  • @next-auth/prisma-adapter prod — dist-only: no readable source
  • @radix-ui/react-switch prod — dist-only: no readable source
  • @radix-ui/react-tabs prod — dist-only: no readable source
  • @radix-ui/react-toggle prod — dist-only: no readable source
  • @radix-ui/react-toggle-group prod — dist-only: no readable source
  • @radix-ui/react-tooltip prod — dist-only: no readable source
  • @t3-oss/env-nextjs prod — dist-only: no readable source
  • bullmq prod — dist-only: no readable source
  • class-variance-authority prod — dist-only: no readable source
  • cmdk prod — dist-only: no readable source
  • https-proxy-agent prod — dist-only: no readable source
  • json-schema-faker prod — dist-only: no readable source
  • next prod — tarball exceeds byte cap
  • next-themes prod — dist-only: no readable source
  • prexit prod — scan budget exceeded
  • prism-react-renderer prod — scan budget exceeded
  • protobufjs prod — scan budget exceeded
  • rate-limiter-flexible prod — scan budget exceeded
  • react prod — scan budget exceeded
  • react-day-picker prod — scan budget exceeded
  • react-dom prod — scan budget exceeded
  • react-dropzone prod — scan budget exceeded
  • react-grid-layout prod — scan budget exceeded
  • react-hook-form prod — scan budget exceeded
  • react-icons prod — scan budget exceeded
  • react-markdown prod — scan budget exceeded
  • react-resizable prod — scan budget exceeded
  • react-resizable-panels prod — scan budget exceeded
  • react-responsive prod — scan budget exceeded
  • react18-json-view prod — scan budget exceeded
  • recharts prod — scan budget exceeded
  • remark-gfm prod — scan budget exceeded
  • sonner prod — scan budget exceeded
  • streamdown prod — scan budget exceeded
  • stripe prod — scan budget exceeded
  • superjson prod — scan budget exceeded
  • tailwind-merge prod — scan budget exceeded
  • tailwindcss-animate prod — scan budget exceeded
  • use-query-params prod — scan budget exceeded
  • uuid prod — scan budget exceeded
  • vaul prod — scan budget exceeded
  • yaml prod — scan budget exceeded
  • zod prod — scan budget exceeded
  • zustand prod — scan budget exceeded
  • @anthropic-ai/tokenizer prod — scan budget exceeded
  • @opentelemetry/instrumentation-express prod — scan budget exceeded
  • @opentelemetry/instrumentation-undici prod — scan budget exceeded
  • @prisma/client prod — scan budget exceeded
  • exponential-backoff prod — scan budget exceeded
  • express prod — scan budget exceeded
  • helmet prod — scan budget exceeded
  • p-limit prod — scan budget exceeded
  • tiktoken prod — scan budget exceeded
  • @eslint/js prod — scan budget exceeded
  • @repo/eslint-plugin prod — scan budget exceeded
  • eslint-config-next prod — scan budget exceeded
  • eslint-config-prettier prod — scan budget exceeded
  • eslint-config-turbo prod — scan budget exceeded
  • eslint-plugin-only-warn prod — scan budget exceeded
  • typescript-eslint prod — scan budget exceeded
  • @ai-sdk/anthropic prod — scan budget exceeded
  • @ai-sdk/azure prod — scan budget exceeded
  • @ai-sdk/google prod — scan budget exceeded
  • @ai-sdk/google-vertex prod — scan budget exceeded
  • @ai-sdk/openai prod — scan budget exceeded
  • @ai-sdk/openai-compatible prod — scan budget exceeded
  • @aws-sdk/client-cloudwatch prod — scan budget exceeded
  • @aws-sdk/client-lambda prod — scan budget exceeded
  • @aws-sdk/client-s3 prod — scan budget exceeded
  • @aws-sdk/client-sesv2 prod — scan budget exceeded
  • @aws-sdk/lib-storage prod — scan budget exceeded
  • @aws-sdk/s3-request-presigner prod — scan budget exceeded
  • @azure/storage-blob prod — scan budget exceeded
  • @clickhouse/client prod — scan budget exceeded
  • @google-cloud/storage prod — scan budget exceeded
  • @opentelemetry/otlp-transformer prod — scan budget exceeded
  • @react-email/components prod — scan budget exceeded
  • @react-email/render prod — scan budget exceeded
  • @slack/oauth prod — scan budget exceeded
  • @slack/web-api prod — scan budget exceeded
  • @smithy/node-http-handler prod — scan budget exceeded
  • ai prod — scan budget exceeded
  • ajv prod — scan budget exceeded
  • ajv-formats prod — scan budget exceeded
  • google-auth-library prod — scan budget exceeded
  • ipaddr.js prod — scan budget exceeded
  • langfuse-langchain prod — scan budget exceeded
  • lossless-json prod — scan budget exceeded
  • lru-cache prod — scan budget exceeded
  • nodemailer prod — scan budget exceeded
  • oci-common prod — scan budget exceeded
  • oci-objectstorage prod — scan budget exceeded
  • safe-regex2 prod — scan budget exceeded
  • slackify-markdown prod — scan budget exceeded
  • undici prod — scan budget exceeded
  • winston prod — scan budget exceeded