Close Open Privacy Scan
App Privacy Score
High risk · 2854 finding(s)
Based on: 62 first-party package(s) · 67/101 deps analyzed
Dependency score: 12 (High risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Potential data exfiltration in application code
External domains:
0.woxav30days.streamlit.app::ffff:192.168.0.1a-za-z0-9-a-za-z0-9._-a.comabc123.transform.us-east-1.on.awsabcdefghijklmnopqrstuvwxyz.appsync-api.us-east-1.amazonaws.comaccess.redhat.comaccounts.google.comaltair-viz.github.ioamzn-s3-demo-bucket.s3.amazonaws.comapi-mcp.global.api.awsapi.contentrecs.docs.aws.comapi.github.comapi.openai.comapi.transformaps-workspaces.us-east-1.amazonaws.comarrow.apache.orgarstechnica.comarvados.orgarxiv.orgauth.openai.comauth0.comavro.apache.orgaws-sagemaker-hyperpod-cluster-setup-us-east-1-prod.s3.us-east-1.amazonaws.comaws.amazon.comaws.github.ioawslabs.github.iob.combitbucket.orgblog.famzah.netblog.ganssle.iobootlin.comboto3.amazonaws.combrotlipy.readthedocs.iobugs.python.orgcassandra.apache.orgcdn.jsdelivr.netcheckip.amazonaws.comchevrotain.ioclick.pocoo.orgclickhouse.comcloud.google.comcode.activestate.comcodeload.github.comcoloredlogs.readthedocs.iocoloredlogs.rtfd.orgcommoncrawl.orgcommonmark.orgcommonwl.orgconsole.aws.amazon.comconverter.swagger.iocookbook.openai.comcore.telegram.orgcryptography.iocvs.pgfoundry.orgcwl-utils.readthedocs.iod-xxx.awsapps.comd-xxxxxxxxxx.awsapps.comd1ni2b6xgvw0s0.cloudfront.netd38p8g9d7yc7ms.cloudfront.netdaft.gateway.scarf.shdata-apis.orgdata.commoncrawl.orgdata.iana.orgdata.streamlit.iodata.un.orgdatastax-oss.atlassian.netdatatracker.ietf.orgdeckgl.readthedocs.iodelta-io.github.iodev.mysql.comdev.w3.orgdeveloper.mozilla.orgdevelopers.google.comdiscuss.python.orgdiscuss.streamlit.iodoc-area-chart-steamgraph.streamlit.appdoc-area-chart.streamlit.appdoc-area-chart1.streamlit.appdoc-area-chart2.streamlit.appdoc-areachart-column.streamlit.appdoc-audio-column.streamlit.appdoc-audio-input-high-rate.streamlit.appdoc-audio-input.streamlit.appdoc-audio-purr.streamlit.appdoc-audio.streamlit.appdoc-badge.streamlit.appdoc-bar-chart-horizontal.streamlit.appdoc-bar-chart-unstacked.streamlit.appdoc-bar-chart.streamlit.appdoc-bar-chart1.streamlit.appdoc-bar-chart2.streamlit.appdoc-barchart-column.streamlit.appdoc-buton.streamlit.appdoc-button-icons.streamlit.appdoc-button-shortcuts.streamlit.appdoc-camera-input.streamlit.appdoc-chart-events-plotly-selection-state.streamlit.appdoc-chart-events-plotly-state.streamlit.appdoc-chart-events-vega-lite-state.streamlit.appdoc-chat-input-audio.streamlit.appdoc-chat-input-file-uploader.streamlit.appdoc-chat-input-inline.streamlit.appdoc-chat-input-session-state.streamlit.appdoc-chat-input.streamlit.appdoc-chat-message-user.streamlit.appdoc-chat-message-user1.streamlit.appdoc-checkbox-column.streamlit.appdoc-checkbox.streamlit.appdoc-code-ascii.streamlit.appdoc-code.streamlit.appdoc-color-picker.streamlit.appdoc-column.streamlit.appdoc-columns-borders.streamlit.appdoc-columns-bottom-widgets.streamlit.appdoc-columns-vertical-alignment.streamlit.appdoc-columns1.streamlit.appdoc-columns2.streamlit.appdoc-components-cleanup-function.streamlit.appdoc-components-custom-anchors.streamlit.appdoc-components-interactive-svg.streamlit.appdoc-components-markdown-links.streamlit.appdoc-components-tailwind-button.streamlit.appdoc-components-text-input.streamlit.appdoc-container1.streamlit.appdoc-container2.streamlit.appdoc-container3.streamlit.appdoc-container4.streamlit.appdoc-container5.streamlit.appdoc-data-editor-config.streamlit.appdoc-data-editor.streamlit.appdoc-data-editor1.streamlit.appdoc-dataframe-config-index.streamlit.appdoc-dataframe-config.streamlit.appdoc-dataframe-events-selection-state.streamlit.appdoc-dataframe-programmatic-selections.streamlit.appdoc-dataframe.streamlit.appdoc-dataframe1.streamlit.appdoc-date-column.streamlit.appdoc-date-input-empty.streamlit.appdoc-date-input.streamlit.appdoc-date-input1.streamlit.appdoc-datetime-column.streamlit.appdoc-datetime-input-empty.streamlit.appdoc-datetime-input.streamlit.appdoc-download-button-csv.streamlit.appdoc-download-button-deferred.streamlit.appdoc-download-button-file.streamlit.appdoc-download-button-text.streamlit.appdoc-empty-placeholder.streamlit.appdoc-empty.streamlit.appdoc-expander-callback.streamlit.appdoc-expander-conditional-outside.streamlit.appdoc-expander-lazy-load.streamlit.appdoc-expander.streamlit.appdoc-feedback-stars.streamlit.appdoc-feedback-thumbs.streamlit.appdoc-file-uploader-directory.streamlit.appdoc-file-uploader.streamlit.appdoc-form1.streamlit.appdoc-form2.streamlit.appdoc-fragment-balloons.streamlit.appdoc-fragment-rerun.streamlit.appdoc-fragment.streamlit.appdoc-graphviz-chart.streamlit.appdoc-header.streamlit.appdoc-html.streamlit.appdoc-image-column.streamlit.appdoc-image.streamlit.appdoc-json-column.streamlit.appdoc-json.streamlit.appdoc-line-chart.streamlit.appdoc-line-chart1.streamlit.appdoc-line-chart2.streamlit.appdoc-linechart-column.streamlit.appdoc-link-button.streamlit.appdoc-link-column.streamlit.appdoc-list-column.streamlit.appdoc-logo.streamlit.appdoc-map-color.streamlit.appdoc-map.streamlit.appdoc-markdown-column.streamlit.appdoc-markdown.streamlit.appdoc-menu-button.streamlit.appdoc-mermaid-chart.streamlit.appdoc-metric-example1.streamlit.appdoc-metric-example2.streamlit.appdoc-metric-example3.streamlit.appdoc-metric-example4.streamlit.appdoc-metric-example5.streamlit.appdoc-modal-dialog.streamlit.appdoc-multiselect-accept-new-options.streamlit.appdoc-multiselect-column-1.streamlit.appdoc-multiselect-column-2.streamlit.appdoc-multiselect.streamlit.appdoc-navigation-example-1.streamlit.appdoc-navigation-example-2.streamlit.appdoc-navigation-multipage-widgets.streamlit.appdoc-navigation-top.streamlit.appdoc-number-column.streamlit.appdoc-number-input-empty.streamlit.appdoc-number-input.streamlit.appdoc-page-link-query-params.streamlit.appdoc-page-link.streamlit.appdoc-pagination-dataframe.streamlit.appdoc-pagination.streamlit.appdoc-pills-multi.streamlit.appdoc-pills-single.streamlit.appdoc-plotly-chart-config.streamlit.appdoc-plotly-chart.streamlit.appdoc-popover-callback.streamlit.appdoc-popover-conditional-outside.streamlit.appdoc-popover-lazy-load.streamlit.appdoc-popover.streamlit.appdoc-popover2.streamlit.appdoc-progress-column.streamlit.appdoc-pydeck-chart.streamlit.appdoc-pydeck-event-state-selections.streamlit.appdoc-pyplot.streamlit.appdoc-radio-empty.streamlit.appdoc-radio.streamlit.appdoc-scatter-chart.streamlit.appdoc-scatter-chart1.streamlit.appdoc-scatter-chart2.streamlit.appdoc-segmented-control-multi.streamlit.appdoc-segmented-control-single.streamlit.appdoc-select-slider.streamlit.appdoc-selectbox-accept-new-options.streamlit.appdoc-selectbox-column.streamlit.appdoc-selectbox-empty.streamlit.appdoc-selectbox.streamlit.appdoc-skeleton-context.streamlit.appdoc-skeleton-standalone.streamlit.appdoc-slider.streamlit.appdoc-space-horizontal.streamlit.appdoc-space-vertical.streamlit.appdoc-spinner.streamlit.appdoc-status-exception.streamlit.appdoc-status-progress.streamlit.appdoc-status-toast.streamlit.appdoc-status-toast1.streamlit.appdoc-status-toast2.streamlit.appdoc-status-update.streamlit.appdoc-status.streamlit.appdoc-string.streamlit.appdoc-string1.streamlit.appdoc-string2.streamlit.appdoc-subheader.streamlit.appdoc-switch-page-query-params.streamlit.appdoc-switch-page.streamlit.appdoc-table-auto-header.streamlit.appdoc-table-confusion.streamlit.appdoc-table-hide-header-and-index.streamlit.appdoc-table-horizontal-border.streamlit.appdoc-tabs-callback.streamlit.appdoc-tabs-conditional-outside.streamlit.appdoc-tabs-lazy-load.streamlit.appdoc-tabs1.streamlit.appdoc-tabs2.streamlit.appdoc-tabs3.streamlit.appdoc-text-area.streamlit.appdoc-text-column.streamlit.appdoc-text-input.streamlit.appdoc-text.streamlit.appdoc-time-column.streamlit.appdoc-time-input-empty.streamlit.appdoc-time-input.streamlit.appdoc-title.streamlit.appdoc-toggle.streamlit.appdoc-vega-lite-chart.streamlit.appdoc-video-column.streamlit.appdoc-video-subtitle-inputs.streamlit.appdoc-video-subtitles.streamlit.appdoc-video.streamlit.appdoc-write-stream-data.streamlit.appdoc-write1.streamlit.appdoc-write2.streamlit.appdoc-write3.streamlit.appdochub.mongodb.orgdockstore.orgdocs.amazonaws.cndocs.anthropic.comdocs.atlas.mongodb.comdocs.aws.amazon.comdocs.columnar.techdocs.daft.aidocs.dask.orgdocs.databricks.comdocs.datastax.comdocs.delta.iodocs.docker.comdocs.influxdata.comdocs.langchain.comdocs.microsoft.comdocs.oasis-open.orgdocs.oracle.comdocs.pola.rsdocs.pydantic.devdocs.pytest.orgdocs.python.orgdocs.ray.iodocs.risingwave.comdocs.rsdocs.snowflake.comdocs.sqlalchemy.orgdocs.starrocks.iodocs.streamlit.iodocs.teradata.comdocusaurus.iodoi.orgduckdb.orged25519.cr.yp.toen.wikipedia.orgerrors.pydantic.devexam_ple.comexample-resource.azure.openai.comexamples.k8s.ioextras.streamlit.appfacelessuser.github.iofastapi.tiangolo.comfastexcel.toucantoco.devfaucet.circle.comfb.mefd00:ec2::254filesystem-spec.readthedocs.iofonts.google.comfonts.googleapis.comfoo.comforum.omz-software.comgateway-api.sigs.k8s.iogit.k8s.iogit.kernel.orggithub.comgithub.github.comgitlab.comglide.valkey.iogo.devgoessner.netgofastmcp.comgolang.orggoogle.comgraphviz.orghelp.openai.comhtml.spec.whatwg.orghttpbin.orghttpwg.orghuggingface.cohumanfriendly.readthedocs.iohynek.mehypothesis.readthedocs.ioiceberg.apache.orgieeexplore.ieee.orgilpubs.stanford.eduindex.docker.ioinfluxdb-client.readthedocs.ioissues.apache.orgissues.k8s.ioissues.streamlit.appjax.readthedocs.iojqlang.github.iojqlang.orgjshint.comjson-schema.orgk8s.iokatex.orgknowledge-mcp.global.api.awskubernetes-csi.github.iokubernetes.iolance-format.github.iolancedb.github.iolearn.microsoft.comlh3.googleusercontent.comlinux.die.netlinuxdevcenter.comlists.sourceforge.netlocalhost.tiangolo.comlogin.microsoftonline.commail.python.orgman7.orgmanagement.azure.commapbox.commatplotlib.orgmcpserver.eks-beta.us-west-2.api.awsmermaid.js.orgmetacpan.orgminiwdl.readthedocs.iomodel-spec.openai.commodelcontextprotocol.iomomentjs.commongodb.commsdn.microsoft.commypy.readthedocs.iomüller.denats.ionickeljoke.vercel.appno-color.orgnpms.ionull.python.orgnumpy.orgocsp.verisign.comopenai.comopenapi-generator.techopenapis.orgopenid.netopenpyxl.readthedocs.ioopenrouter.aiopenwdl.orgorcid.orgother.compackaging.python.orgpandas.pydata.orgpds-rings.seti.orgpendulum.eustace.iopeps.python.orgpika.rtfd.orgpkg.go.devplatform.claude.complatform.openai.complot.lyplotly.compola.rsposit-dev.github.ioprometheus.ioproxy.comproxy.domain.orgproxy.search.docs.aws.compurl.orgpushgateway.localpy.iceberg.apache.orgpydantic-docs.helpmanual.iopypi.orgpypi.python.orgpython-devtools.helpmanual.iopython-oracledb.readthedocs.iopython.example.orgpython.langchain.compython.orgpytorch.orgpyyaml.orgraw.githubusercontent.comreact.devreactjs.orgregistry.opendata.awsrepost.awsrequests.readthedocs.iorich.readthedocs.iorightfootin.blogspot.comroadmap.streamlit.approlldown.rss3-us-west-2.amazonaws.coms3.console.aws.amazon.coms3tables.us-west-2.amazonaws.comschema.orgsdk.amazonaws.comserverfault.comservice.ecs.region.on.awsservicereference.us-east-1.amazonaws.comsethmlarson.devsetuptools.readthedocs.iosfu-db.github.ioshare-demo.streamlit.ioshare-head.streamlit.ioshare-staging.streamlit.ioshare.streamlit.iosome.hostnamesourceforge.netspark.apache.orgspdx.devsqlglot.comstackoverflow.comstarlette.devstates-language.netstatic.streamlit.iostorage.azure.comstorage.googleapis.comstrandsagents.comstreamlit-demo-data.s3-us-west-2.amazonaws.comstreamlit.iosupport.microsoft.comsupport.orcid.orgsvrintl-g3-aia.verisign.comsvrintl-g3-crl.verisign.comswagger.iotestca.pythontest.nettimeapi.iotoml.iotools.ietf.orgtrino.iotruststore.pki.rds.amazonaws.comturbopuffer.comtwistedmatrix.comtwitter.comtyper.tiangolo.comunpkg.comupload.wikimedia.orgurllib3.readthedocs.ious-east-1.console.aws.amazon.comus-west-2-1.aws.cloud2.influxdata.comuse.typekit.netvalkey-io.github.iovalkey.iovega.github.iovisjs.github.iovote.comw3id.orgweb.archive.orgwebsockets.readthedocs.iowheel.readthedocs.iowiki.centos.orgwiki.openstreetmap.orgwww.apache.orgwww.cacert.orgwww.cl.cam.ac.ukwww.commonwl.orgwww.cracker.comwww.crummy.comwww.databricks.comwww.datastax.comwww.dnspython.orgwww.egenix.comwww.example.珠宝www.extremelycoolapp.comwww.freebsd.orgwww.freetds.orgwww.gevent.orgwww.github.comwww.gmarts.orgwww.gnu.orgwww.google.comwww.googleapis.comwww.gossamer-threads.comwww.gzip.orgwww.iana.orgwww.json.orgwww.libreoffice.orgwww.linuxprogrammingblog.comwww.mapbox.comwww.microsoft.comwww.mongodb.comwww.openarchives.orgwww.oracle.comwww.oreilly.comwww.pcre.orgwww.perl.orgwww.picloud.comwww.postgresql.orgwww.pyopenssl.orgwww.python.orgwww.rabbitmq.comwww.rfc-editor.orgwww.secg.orgwww.sqlite.orgwww.systutorials.comwww.tondering.dkwww.unicode.orgwww.w3.orgwww.xudongz.comwww.youtube.comxlsxwriter.readthedocs.ioxmfe3hc3pk.execute-api.us-east-2.amazonaws.comxmlns.comxn--fiqs8s.icom.museumxxhash.comyahoo.comyaml.devyaml.orgyoutu.bezopecomponent.readthedocs.io
- 1source
pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 - 2sink
pkgs/python/[email protected]/tests_integ/tools/test_code.py:257
- 1source
pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 - 2sink
pkgs/python/[email protected]/tests_integ/tools/test_code.py:269
- 1source
pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 - 2sink
pkgs/python/[email protected]/tests_integ/tools/test_code.py:310
hub Dependency data flows (1)
- 1source
pkgs/python/[email protected]/pyiceberg/io/fsspec.py:102 - 2sink
pkgs/python/[email protected]/pyiceberg/io/fsspec.py:113
</> First-Party Code
first-party (python): samples/mcp-integration-with-kb
python first-partyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
first-party (python): samples/mcp-integration-with-nova-canvas
python first-partyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
with open(image_path, 'rb') as file:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/amazon-bedrock-agentcore-mcp-server
python first-partyexpand_more 19 low-confidence finding(s)
low env_fs — Environment-variable access. 18 locations
with urllib.request.urlopen(req, timeout=doc_config.timeout) as r: # nosec
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/amazon-kendra-index-mcp-server
python first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
first-party (python): src/amazon-keyspaces-mcp-server
python first-partyexpand_more 8 low-confidence finding(s)
low env_fs — Environment-variable access. 8 locations
first-party (python): src/amazon-mq-mcp-server
python first-partyexpand_more 8 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
response = requests.request(method, url, headers=self.headers, json=data, verify=True)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
low env_fs — Filesystem access. 5 locations
first-party (python): src/amazon-neptune-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): src/amazon-qbusiness-anonymous-mcp-server
python first-partyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
first-party (python): src/amazon-qindex-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): src/amazon-sns-sqs-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): src/amazon-translate-mcp-server
python first-partyexpand_more 21 low-confidence finding(s)
low env_fs — Environment-variable access. 20 locations
with open(file_path_obj, 'rb') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/aurora-dsql-mcp-server
python first-partyexpand_more 1 low-confidence finding(s)
response = await client.post(knowledge_server, json=payload)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/aws-api-mcp-server
python first-partyexpand_more 25 low-confidence finding(s)
low env_fs — Filesystem access. 4 locations
low env_fs — Environment-variable access. 18 locations
response = requests.get(SERVICE_REFERENCE_URL, timeout=DEFAULT_REQUEST_TIMEOUT).json()
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
first-party (python): src/aws-appsync-mcp-server
python first-partyexpand_more 1 low-confidence finding(s)
profile_name=os.getenv('AWS_PROFILE'), region_name=os.getenv('AWS_REGION', 'us-east-1')
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/aws-bedrock-custom-model-import-mcp-server
python first-partyexpand_more 6 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
first-party (python): src/aws-dataprocessing-mcp-server
python first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
first-party (python): src/aws-documentation-mcp-server
python first-partyexpand_more 10 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 7 locations
first-party (python): src/aws-for-sap-management-mcp-server
python first-partyexpand_more 1 low-confidence finding(s)
profile_name = getenv('AWS_PROFILE', None)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/aws-healthomics-mcp-server
python first-partyexpand_more 26 low-confidence finding(s)
low env_fs — Environment-variable access. 19 locations
low env_fs — Filesystem access. 7 locations
repo/src/aws-healthomics-mcp-server/awslabs/aws_healthomics_mcp_server/tools/workflow_linting.py:200
repo/src/aws-healthomics-mcp-server/awslabs/aws_healthomics_mcp_server/tools/workflow_linting.py:319
repo/src/aws-healthomics-mcp-server/awslabs/aws_healthomics_mcp_server/utils/content_resolver.py:149
repo/src/aws-healthomics-mcp-server/awslabs/aws_healthomics_mcp_server/utils/content_resolver.py:152
first-party (python): src/aws-iac-mcp-server
python first-partyexpand_more 7 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
with open(_bundled_rules_path(), 'r') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/aws-iot-sitewise-mcp-server
python first-partyexpand_more 3 low-confidence finding(s)
first-party (python): src/aws-location-mcp-server
python first-partyexpand_more 9 low-confidence finding(s)
low env_fs — Environment-variable access. 9 locations
first-party (python): src/aws-network-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): src/aws-pricing-mcp-server
python first-partyexpand_more 8 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
low env_fs — Environment-variable access. 5 locations
first-party (python): src/aws-serverless-mcp-server
python first-partyexpand_more 16 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
low env_fs — Filesystem access. 9 locations
response = requests.get(url, headers=default_headers, timeout=30)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/aws-support-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
first-party (python): src/aws-transform-mcp-server
python first-partyexpand_more 20 low-confidence finding(s)
low env_fs — Environment-variable access. 11 locations
low env_fs — Filesystem access. 4 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
first-party (python): src/bedrock-kb-retrieval-mcp-server
python first-partyexpand_more 6 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
first-party (python): src/billing-cost-management-mcp-server
python first-partyexpand_more 14 low-confidence finding(s)
low env_fs — Environment-variable access. 13 locations
with open(template_path, 'r') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/ccapi-mcp-server
python first-partyexpand_more 35 low-confidence finding(s)
low env_fs — Environment-variable access. 30 locations
low env_fs — Filesystem access. 5 locations
first-party (python): src/cloudtrail-mcp-server
python first-partyexpand_more 1 low-confidence finding(s)
if aws_profile := os.environ.get('AWS_PROFILE'):
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/cloudwatch-applicationsignals-mcp-server
python first-partyexpand_more 38 low-confidence finding(s)
low env_fs — Environment-variable access. 24 locations
low env_fs — Filesystem access. 11 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
first-party (python): src/cloudwatch-mcp-server
python first-partyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
with open(metadata_file, 'r', encoding='utf-8') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/document-loader-mcp-server
python first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
first-party (python): src/dynamodb-mcp-server
python first-partyexpand_more 39 low-confidence finding(s)
low env_fs — Filesystem access. 25 locations
low env_fs — Environment-variable access. 13 locations
with urllib.request.urlopen( # nosec B310
DynamoDBLocalConfig.DOWNLOAD_URL, timeout=DynamoDBLocalConfig.DOWNLOAD_TIMEOUT
) as response:
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/ecs-mcp-server
python first-partyexpand_more 20 low-confidence finding(s)
low env_fs — Filesystem access. 7 locations
low env_fs — Environment-variable access. 13 locations
first-party (python): src/eks-mcp-server
python first-partyexpand_more 22 low-confidence finding(s)
low env_fs — Environment-variable access. 11 locations
low env_fs — Filesystem access. 9 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
first-party (python): src/elasticache-mcp-server
python first-partyexpand_more 6 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
first-party (python): src/finch-mcp-server
python first-partyexpand_more 13 low-confidence finding(s)
low env_fs — Environment-variable access. 10 locations
first-party (python): src/healthlake-mcp-server
python first-partyexpand_more 8 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 7 locations
logger.add(sys.stderr, level=os.getenv('MCP_LOG_LEVEL', 'WARNING'))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/lambda-tool-mcp-server
python first-partyexpand_more 7 low-confidence finding(s)
low env_fs — Environment-variable access. 7 locations
first-party (python): src/mcp-lambda-handler
python first-partyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
first-party (python): src/memcached-mcp-server
python first-partyexpand_more 12 low-confidence finding(s)
low env_fs — Environment-variable access. 11 locations
result = client.get(key)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/mssql-mcp-server
python first-partyexpand_more 2 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
first-party (python): src/mysql-mcp-server
python first-partyexpand_more 3 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
with urllib.request.urlopen( # nosec B310
_RDS_CA_BUNDLE_URL, timeout=30, context=ctx
) as resp:
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/openapi-mcp-server
python first-partyexpand_more 25 low-confidence finding(s)
low env_fs — Environment-variable access. 17 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
first-party (python): src/prometheus-mcp-server
python first-partyexpand_more 15 low-confidence finding(s)
low env_fs — Environment-variable access. 15 locations
first-party (python): src/redshift-mcp-server
python first-partyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
first-party (python): src/roda-mcp-server
python first-partyexpand_more 3 low-confidence finding(s)
logger.add(sys.stderr, level=os.getenv('FASTMCP_LOG_LEVEL', 'WARNING'))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
first-party (python): src/s3-tables-mcp-server
python first-partyexpand_more 9 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
low env_fs — Filesystem access. 4 locations
first-party (python): src/sagemaker-ai-mcp-server
python first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
with open(validated_path, 'r') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
first-party (python): src/security-agent-mcp-server
python first-partyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low env_fs — Filesystem access. 2 locations
first-party (python): src/stepfunctions-tool-mcp-server
python first-partyexpand_more 7 low-confidence finding(s)
low env_fs — Environment-variable access. 7 locations
first-party (python): src/timestream-for-influxdb-mcp-server
python first-partyexpand_more 6 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
first-party (python): src/valkey-mcp-server
python first-partyexpand_more 30 low-confidence finding(s)
low env_fs — Environment-variable access. 28 locations
with open(ca_path, 'rb') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
response = await self._client.post(
f'{self.base_url}/api/embeddings',
json={'model': self.model, 'prompt': text},
)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (python): src/well-architected-security-mcp-server
python first-partyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
with open(file_path, "r") as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
bedrock-agentcore
python dependency from opentelemetry import trace
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry.sdk.trace import SpanProcessor # type: ignore[import]
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
from opentelemetry import baggage as otel_baggage
A telemetry/analytics SDK is used; event data is sent to a third-party collector.
Fix: Ensure user consent and a lawful basis; strip PII from event payloads.
print(f" Created interpreter: {interpreter_id}")
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
print(f" Interpreter status: {info['status']}")
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
print(f" Cleaned up interpreter: {interpreter_id}")
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 184 low-confidence finding(s)
low env_fs — Filesystem access. 20 locations
low env_fs — Environment-variable access. 151 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 13 locations
pyiceberg
python dependency response = requests.post(f"{signer_url}/{signer_endpoint.strip()}", headers=signer_headers, json=signer_body)
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
expand_more 22 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low env_fs — Filesystem access. 5 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 14 locations
boto3
python dependencyexpand_more 4 low-confidence finding(s)
botocore
python dependencyexpand_more 36 low-confidence finding(s)
low env_fs — Environment-variable access. 31 locations
low env_fs — Filesystem access. 5 locations
cassandra-driver
python dependencyexpand_more 4 low-confidence finding(s)
if not os.getenv(CQLENG_ALLOW_SCHEMA_MANAGEMENT):
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Filesystem access. 2 locations
response = urlopen(url, context=config.ssl_context, timeout=timeout)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
cfn-lint
python dependencyexpand_more 29 low-confidence finding(s)
low env_fs — Environment-variable access. 5 locations
low env_fs — Filesystem access. 21 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
coloredlogs
python dependencyexpand_more 24 low-confidence finding(s)
low env_fs — Environment-variable access. 18 locations
low env_fs — Filesystem access. 6 locations
cwltool
python dependencyexpand_more 87 low-confidence finding(s)
low env_fs — Filesystem access. 41 locations
low env_fs — Environment-variable access. 43 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
daft
python dependencyexpand_more 28 low-confidence finding(s)
low env_fs — Environment-variable access. 23 locations
low env_fs — Filesystem access. 2 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
docker
python dependencyexpand_more 22 low-confidence finding(s)
low env_fs — Filesystem access. 15 locations
low env_fs — Environment-variable access. 7 locations
fastapi
python dependencyexpand_more 70 low-confidence finding(s)
low env_fs — Filesystem access. 55 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 12 locations
os.environ["DYLD_FALLBACK_LIBRARY_PATH"] = "/opt/homebrew/lib"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
filelock
python dependencyexpand_more 6 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
low env_fs — Environment-variable access. 4 locations
gevent
python dependencyexpand_more 996 low-confidence finding(s)
low env_fs — Environment-variable access. 265 locations
low env_fs — Filesystem access. 446 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 185 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 100 locations
httpx
python dependencyexpand_more 4 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
influxdb-client
python dependencyexpand_more 26 low-confidence finding(s)
low env_fs — Filesystem access. 7 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
low env_fs — Environment-variable access. 14 locations
jinja2
python dependencyexpand_more 7 low-confidence finding(s)
low env_fs — Filesystem access. 6 locations
code = self.client.get(self.prefix + bucket.key)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
kubernetes
python dependencyexpand_more 68 low-confidence finding(s)
low env_fs — Filesystem access. 41 locations
low env_fs — Environment-variable access. 17 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 10 locations
langchain-aws
python dependencyexpand_more 17 low-confidence finding(s)
low env_fs — Environment-variable access. 13 locations
low env_fs — Filesystem access. 4 locations
langchain-mcp-adapters
python dependencyexpand_more 1 low-confidence finding(s)
return _BRACED_VAR_RE.sub(lambda m: os.environ.get(m.group(1), m.group(0)), value)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
loguru
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Environment-variable access. 6 locations
low env_fs — Filesystem access. 3 locations
mcp
python dependencyexpand_more 39 low-confidence finding(s)
low env_fs — Environment-variable access. 16 locations
pkgs/python/[email protected]/examples/clients/simple-auth-client/mcp_simple_auth_client/main.py:343
pkgs/python/[email protected]/examples/clients/simple-auth-client/mcp_simple_auth_client/main.py:344
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 6 locations
low env_fs — Filesystem access. 15 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
miniwdl
python dependencyexpand_more 54 low-confidence finding(s)
low env_fs — Environment-variable access. 23 locations
low env_fs — Filesystem access. 31 locations
openai
python dependencyexpand_more 69 low-confidence finding(s)
low env_fs — Filesystem access. 16 locations
low env_fs — Environment-variable access. 47 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 4 locations
openapi-spec-validator
python dependencyexpand_more 1 low-confidence finding(s)
return os.getenv("OPENAPI_SPEC_VALIDATOR_WARN_DEPRECATED", "1") != "0"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
oracledb
python dependencyexpand_more 5 low-confidence finding(s)
extra_compile_args = os.environ.get("PYO_COMPILE_ARGS", "").split()
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Filesystem access. 3 locations
response = requests.post(
end_user_sec_params.get("authority"), headers=headers, data=payload
)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
polars
python dependencyexpand_more 93 low-confidence finding(s)
low env_fs — Environment-variable access. 89 locations
low env_fs — Filesystem access. 3 locations
with urlopen(path) as f:
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
prance
python dependencyexpand_more 6 low-confidence finding(s)
r = requests.post(
"https://converter.swagger.io/api/convert", data=data, headers=headers
)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
os.environ.get("SYSTEMDRIVE", "C:")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Filesystem access. 3 locations
response = requests.get(url.geturl())
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
prometheus-client
python dependencyexpand_more 21 low-confidence finding(s)
low env_fs — Environment-variable access. 14 locations
low env_fs — Filesystem access. 6 locations
resp = build_opener(base_handler).open(request, timeout=timeout)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
psutil
python dependencyexpand_more 28 low-confidence finding(s)
low env_fs — Filesystem access. 19 locations
low env_fs — Environment-variable access. 7 locations
res = requests.get(url, timeout=REQUEST_TIMEOUT)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
req = urlopen(URL, **kwargs)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
psycopg
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Environment-variable access. 7 locations
low env_fs — Filesystem access. 2 locations
pyarrow
python dependencyexpand_more 21 low-confidence finding(s)
low env_fs — Environment-variable access. 16 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
low env_fs — Filesystem access. 3 locations
pydantic
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 5 locations
pymemcache
python dependencyexpand_more 1 low-confidence finding(s)
return client.get(key, default)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
pymongo
python dependencyexpand_more 117 low-confidence finding(s)
low env_fs — Filesystem access. 20 locations
low env_fs — Environment-variable access. 92 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
pymssql
python dependencyexpand_more 18 low-confidence finding(s)
low env_fs — Environment-variable access. 15 locations
low env_fs — Filesystem access. 3 locations
python-dateutil
python dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 8 locations
name = os.environ["TZ"]
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
python-dotenv
python dependencyexpand_more 11 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
low env_fs — Environment-variable access. 8 locations
python-multipart
python dependencyexpand_more 1 low-confidence finding(s)
tmp_file = open(path, "w+b")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
pyyaml
python dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
requests
python dependencyexpand_more 8 low-confidence finding(s)
low env_fs — Environment-variable access. 8 locations
requests_auth_aws_sigv4
python dependencyexpand_more 6 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
r = requests.request(args.request, args.url, headers=headers, data=post_data,
auth=AWSSigV4(args.service, region=args.region))
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
with open("README.md", "r") as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
ruamel-yaml
python dependencyexpand_more 19 low-confidence finding(s)
low env_fs — Filesystem access. 9 locations
low env_fs — Environment-variable access. 10 locations
sqlglot
python dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 2 locations
with open(pkg_info, encoding="utf-8") as fd:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
sqlparse
python dependencyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
streamlit
python dependencyexpand_more 56 low-confidence finding(s)
low env_fs — Environment-variable access. 19 locations
low env_fs — Filesystem access. 32 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
response_json = requests.get(
"https://data.streamlit.io/metrics.json", timeout=2
).json()
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
thefuzz
python dependencyexpand_more 1 low-confidence finding(s)
with open('README.rst') as f:
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
typing-extensions
python dependencyexpand_more 7 low-confidence finding(s)
low env_fs — Filesystem access. 7 locations
urllib3
python dependencyexpand_more 12 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
low env_fs — Filesystem access. 4 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
uvicorn
python dependencyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low env_fs — Filesystem access. 2 locations
Skipped dependencies
Production
- pillow prod — sdist exceeds byte cap
- langchain-community prod — sdist exceeds byte cap
- boto3-stubs prod — no python source in sdist
- fastmcp prod — sdist exceeds byte cap
- python-Levenshtein prod — no python source in sdist
- guardpycfn prod — no python source in sdist
- playwright prod — no sdist (wheels only)
- awslabs.mysql-mcp-server prod — scan budget exceeded
- awslabs-aws-api-mcp-server prod — scan budget exceeded
- asyncmy prod — scan budget exceeded
- defusedxml prod — scan budget exceeded
- starlette prod — scan budget exceeded
- authlib prod — scan budget exceeded
- numpy prod — scan budget exceeded
- pandas prod — scan budget exceeded
- statsmodels prod — scan budget exceeded
- PyYAML prod — scan budget exceeded
- pdfplumber prod — scan budget exceeded
- markitdown prod — scan budget exceeded
- pdf2image prod — scan budget exceeded
- python-json-logger prod — scan budget exceeded
- setuptools prod — scan budget exceeded
- importlib_resources prod — scan budget exceeded
- python-frontmatter prod — scan budget exceeded
- awscli prod — scan budget exceeded
- gitignorefile prod — scan budget exceeded
- idna prod — scan budget exceeded
- protego prod — scan budget exceeded
- readabilipy prod — scan budget exceeded
- dsql-lint prod — scan budget exceeded
- langdetect prod — scan budget exceeded
- virtualenv prod — scan budget exceeded
- checkov prod — scan budget exceeded
- mypy-boto3-qbusiness prod — scan budget exceeded