Close Open Privacy Scan

bolt Snapshot: commit 47a2904
science engine v1.23
schedule 2026-07-27T16:27:17.390073+00:00

verified_user Possible application data leak

Potential data exfiltration identified in application code.

smart_toy MCP server detected: fastmcp, mcp, openai — detected in dependencies, not a safety judgment.

App Privacy Score

37 /100
High privacy risk — possible application leak

High risk · 2854 finding(s)

Based on: 62 first-party package(s) · 67/101 deps analyzed

Dependency score: 12 (High risk)

bar_chart Score Breakdown

pii_flow −45
egress −15
env_fs −3

list Scan Summary

0 high 7 medium 2847 low
First-party packages: 56
Dependency packages: 49
Ecosystem: python

swap_horiz Potential data exfiltration in application code

External domains: 0.woxav30days.streamlit.app::ffff:192.168.0.1a-za-z0-9-a-za-z0-9._-a.comabc123.transform.us-east-1.on.awsabcdefghijklmnopqrstuvwxyz.appsync-api.us-east-1.amazonaws.comaccess.redhat.comaccounts.google.comaltair-viz.github.ioamzn-s3-demo-bucket.s3.amazonaws.comapi-mcp.global.api.awsapi.contentrecs.docs.aws.comapi.github.comapi.openai.comapi.transformaps-workspaces.us-east-1.amazonaws.comarrow.apache.orgarstechnica.comarvados.orgarxiv.orgauth.openai.comauth0.comavro.apache.orgaws-sagemaker-hyperpod-cluster-setup-us-east-1-prod.s3.us-east-1.amazonaws.comaws.amazon.comaws.github.ioawslabs.github.iob.combitbucket.orgblog.famzah.netblog.ganssle.iobootlin.comboto3.amazonaws.combrotlipy.readthedocs.iobugs.python.orgcassandra.apache.orgcdn.jsdelivr.netcheckip.amazonaws.comchevrotain.ioclick.pocoo.orgclickhouse.comcloud.google.comcode.activestate.comcodeload.github.comcoloredlogs.readthedocs.iocoloredlogs.rtfd.orgcommoncrawl.orgcommonmark.orgcommonwl.orgconsole.aws.amazon.comconverter.swagger.iocookbook.openai.comcore.telegram.orgcryptography.iocvs.pgfoundry.orgcwl-utils.readthedocs.iod-xxx.awsapps.comd-xxxxxxxxxx.awsapps.comd1ni2b6xgvw0s0.cloudfront.netd38p8g9d7yc7ms.cloudfront.netdaft.gateway.scarf.shdata-apis.orgdata.commoncrawl.orgdata.iana.orgdata.streamlit.iodata.un.orgdatastax-oss.atlassian.netdatatracker.ietf.orgdeckgl.readthedocs.iodelta-io.github.iodev.mysql.comdev.w3.orgdeveloper.mozilla.orgdevelopers.google.comdiscuss.python.orgdiscuss.streamlit.iodoc-area-chart-steamgraph.streamlit.appdoc-area-chart.streamlit.appdoc-area-chart1.streamlit.appdoc-area-chart2.streamlit.appdoc-areachart-column.streamlit.appdoc-audio-column.streamlit.appdoc-audio-input-high-rate.streamlit.appdoc-audio-input.streamlit.appdoc-audio-purr.streamlit.appdoc-audio.streamlit.appdoc-badge.streamlit.appdoc-bar-chart-horizontal.streamlit.appdoc-bar-chart-unstacked.streamlit.appdoc-bar-chart.streamlit.appdoc-bar-chart1.streamlit.appdoc-bar-chart2.streamlit.appdoc-barchart-column.streamlit.appdoc-buton.streamlit.appdoc-button-icons.streamlit.appdoc-button-shortcuts.streamlit.appdoc-camera-input.streamlit.appdoc-chart-events-plotly-selection-state.streamlit.appdoc-chart-events-plotly-state.streamlit.appdoc-chart-events-vega-lite-state.streamlit.appdoc-chat-input-audio.streamlit.appdoc-chat-input-file-uploader.streamlit.appdoc-chat-input-inline.streamlit.appdoc-chat-input-session-state.streamlit.appdoc-chat-input.streamlit.appdoc-chat-message-user.streamlit.appdoc-chat-message-user1.streamlit.appdoc-checkbox-column.streamlit.appdoc-checkbox.streamlit.appdoc-code-ascii.streamlit.appdoc-code.streamlit.appdoc-color-picker.streamlit.appdoc-column.streamlit.appdoc-columns-borders.streamlit.appdoc-columns-bottom-widgets.streamlit.appdoc-columns-vertical-alignment.streamlit.appdoc-columns1.streamlit.appdoc-columns2.streamlit.appdoc-components-cleanup-function.streamlit.appdoc-components-custom-anchors.streamlit.appdoc-components-interactive-svg.streamlit.appdoc-components-markdown-links.streamlit.appdoc-components-tailwind-button.streamlit.appdoc-components-text-input.streamlit.appdoc-container1.streamlit.appdoc-container2.streamlit.appdoc-container3.streamlit.appdoc-container4.streamlit.appdoc-container5.streamlit.appdoc-data-editor-config.streamlit.appdoc-data-editor.streamlit.appdoc-data-editor1.streamlit.appdoc-dataframe-config-index.streamlit.appdoc-dataframe-config.streamlit.appdoc-dataframe-events-selection-state.streamlit.appdoc-dataframe-programmatic-selections.streamlit.appdoc-dataframe.streamlit.appdoc-dataframe1.streamlit.appdoc-date-column.streamlit.appdoc-date-input-empty.streamlit.appdoc-date-input.streamlit.appdoc-date-input1.streamlit.appdoc-datetime-column.streamlit.appdoc-datetime-input-empty.streamlit.appdoc-datetime-input.streamlit.appdoc-download-button-csv.streamlit.appdoc-download-button-deferred.streamlit.appdoc-download-button-file.streamlit.appdoc-download-button-text.streamlit.appdoc-empty-placeholder.streamlit.appdoc-empty.streamlit.appdoc-expander-callback.streamlit.appdoc-expander-conditional-outside.streamlit.appdoc-expander-lazy-load.streamlit.appdoc-expander.streamlit.appdoc-feedback-stars.streamlit.appdoc-feedback-thumbs.streamlit.appdoc-file-uploader-directory.streamlit.appdoc-file-uploader.streamlit.appdoc-form1.streamlit.appdoc-form2.streamlit.appdoc-fragment-balloons.streamlit.appdoc-fragment-rerun.streamlit.appdoc-fragment.streamlit.appdoc-graphviz-chart.streamlit.appdoc-header.streamlit.appdoc-html.streamlit.appdoc-image-column.streamlit.appdoc-image.streamlit.appdoc-json-column.streamlit.appdoc-json.streamlit.appdoc-line-chart.streamlit.appdoc-line-chart1.streamlit.appdoc-line-chart2.streamlit.appdoc-linechart-column.streamlit.appdoc-link-button.streamlit.appdoc-link-column.streamlit.appdoc-list-column.streamlit.appdoc-logo.streamlit.appdoc-map-color.streamlit.appdoc-map.streamlit.appdoc-markdown-column.streamlit.appdoc-markdown.streamlit.appdoc-menu-button.streamlit.appdoc-mermaid-chart.streamlit.appdoc-metric-example1.streamlit.appdoc-metric-example2.streamlit.appdoc-metric-example3.streamlit.appdoc-metric-example4.streamlit.appdoc-metric-example5.streamlit.appdoc-modal-dialog.streamlit.appdoc-multiselect-accept-new-options.streamlit.appdoc-multiselect-column-1.streamlit.appdoc-multiselect-column-2.streamlit.appdoc-multiselect.streamlit.appdoc-navigation-example-1.streamlit.appdoc-navigation-example-2.streamlit.appdoc-navigation-multipage-widgets.streamlit.appdoc-navigation-top.streamlit.appdoc-number-column.streamlit.appdoc-number-input-empty.streamlit.appdoc-number-input.streamlit.appdoc-page-link-query-params.streamlit.appdoc-page-link.streamlit.appdoc-pagination-dataframe.streamlit.appdoc-pagination.streamlit.appdoc-pills-multi.streamlit.appdoc-pills-single.streamlit.appdoc-plotly-chart-config.streamlit.appdoc-plotly-chart.streamlit.appdoc-popover-callback.streamlit.appdoc-popover-conditional-outside.streamlit.appdoc-popover-lazy-load.streamlit.appdoc-popover.streamlit.appdoc-popover2.streamlit.appdoc-progress-column.streamlit.appdoc-pydeck-chart.streamlit.appdoc-pydeck-event-state-selections.streamlit.appdoc-pyplot.streamlit.appdoc-radio-empty.streamlit.appdoc-radio.streamlit.appdoc-scatter-chart.streamlit.appdoc-scatter-chart1.streamlit.appdoc-scatter-chart2.streamlit.appdoc-segmented-control-multi.streamlit.appdoc-segmented-control-single.streamlit.appdoc-select-slider.streamlit.appdoc-selectbox-accept-new-options.streamlit.appdoc-selectbox-column.streamlit.appdoc-selectbox-empty.streamlit.appdoc-selectbox.streamlit.appdoc-skeleton-context.streamlit.appdoc-skeleton-standalone.streamlit.appdoc-slider.streamlit.appdoc-space-horizontal.streamlit.appdoc-space-vertical.streamlit.appdoc-spinner.streamlit.appdoc-status-exception.streamlit.appdoc-status-progress.streamlit.appdoc-status-toast.streamlit.appdoc-status-toast1.streamlit.appdoc-status-toast2.streamlit.appdoc-status-update.streamlit.appdoc-status.streamlit.appdoc-string.streamlit.appdoc-string1.streamlit.appdoc-string2.streamlit.appdoc-subheader.streamlit.appdoc-switch-page-query-params.streamlit.appdoc-switch-page.streamlit.appdoc-table-auto-header.streamlit.appdoc-table-confusion.streamlit.appdoc-table-hide-header-and-index.streamlit.appdoc-table-horizontal-border.streamlit.appdoc-tabs-callback.streamlit.appdoc-tabs-conditional-outside.streamlit.appdoc-tabs-lazy-load.streamlit.appdoc-tabs1.streamlit.appdoc-tabs2.streamlit.appdoc-tabs3.streamlit.appdoc-text-area.streamlit.appdoc-text-column.streamlit.appdoc-text-input.streamlit.appdoc-text.streamlit.appdoc-time-column.streamlit.appdoc-time-input-empty.streamlit.appdoc-time-input.streamlit.appdoc-title.streamlit.appdoc-toggle.streamlit.appdoc-vega-lite-chart.streamlit.appdoc-video-column.streamlit.appdoc-video-subtitle-inputs.streamlit.appdoc-video-subtitles.streamlit.appdoc-video.streamlit.appdoc-write-stream-data.streamlit.appdoc-write1.streamlit.appdoc-write2.streamlit.appdoc-write3.streamlit.appdochub.mongodb.orgdockstore.orgdocs.amazonaws.cndocs.anthropic.comdocs.atlas.mongodb.comdocs.aws.amazon.comdocs.columnar.techdocs.daft.aidocs.dask.orgdocs.databricks.comdocs.datastax.comdocs.delta.iodocs.docker.comdocs.influxdata.comdocs.langchain.comdocs.microsoft.comdocs.oasis-open.orgdocs.oracle.comdocs.pola.rsdocs.pydantic.devdocs.pytest.orgdocs.python.orgdocs.ray.iodocs.risingwave.comdocs.rsdocs.snowflake.comdocs.sqlalchemy.orgdocs.starrocks.iodocs.streamlit.iodocs.teradata.comdocusaurus.iodoi.orgduckdb.orged25519.cr.yp.toen.wikipedia.orgerrors.pydantic.devexam_ple.comexample-resource.azure.openai.comexamples.k8s.ioextras.streamlit.appfacelessuser.github.iofastapi.tiangolo.comfastexcel.toucantoco.devfaucet.circle.comfb.mefd00:ec2::254filesystem-spec.readthedocs.iofonts.google.comfonts.googleapis.comfoo.comforum.omz-software.comgateway-api.sigs.k8s.iogit.k8s.iogit.kernel.orggithub.comgithub.github.comgitlab.comglide.valkey.iogo.devgoessner.netgofastmcp.comgolang.orggoogle.comgraphviz.orghelp.openai.comhtml.spec.whatwg.orghttpbin.orghttpwg.orghuggingface.cohumanfriendly.readthedocs.iohynek.mehypothesis.readthedocs.ioiceberg.apache.orgieeexplore.ieee.orgilpubs.stanford.eduindex.docker.ioinfluxdb-client.readthedocs.ioissues.apache.orgissues.k8s.ioissues.streamlit.appjax.readthedocs.iojqlang.github.iojqlang.orgjshint.comjson-schema.orgk8s.iokatex.orgknowledge-mcp.global.api.awskubernetes-csi.github.iokubernetes.iolance-format.github.iolancedb.github.iolearn.microsoft.comlh3.googleusercontent.comlinux.die.netlinuxdevcenter.comlists.sourceforge.netlocalhost.tiangolo.comlogin.microsoftonline.commail.python.orgman7.orgmanagement.azure.commapbox.commatplotlib.orgmcpserver.eks-beta.us-west-2.api.awsmermaid.js.orgmetacpan.orgminiwdl.readthedocs.iomodel-spec.openai.commodelcontextprotocol.iomomentjs.commongodb.commsdn.microsoft.commypy.readthedocs.iomüller.denats.ionickeljoke.vercel.appno-color.orgnpms.ionull.python.orgnumpy.orgocsp.verisign.comopenai.comopenapi-generator.techopenapis.orgopenid.netopenpyxl.readthedocs.ioopenrouter.aiopenwdl.orgorcid.orgother.compackaging.python.orgpandas.pydata.orgpds-rings.seti.orgpendulum.eustace.iopeps.python.orgpika.rtfd.orgpkg.go.devplatform.claude.complatform.openai.complot.lyplotly.compola.rsposit-dev.github.ioprometheus.ioproxy.comproxy.domain.orgproxy.search.docs.aws.compurl.orgpushgateway.localpy.iceberg.apache.orgpydantic-docs.helpmanual.iopypi.orgpypi.python.orgpython-devtools.helpmanual.iopython-oracledb.readthedocs.iopython.example.orgpython.langchain.compython.orgpytorch.orgpyyaml.orgraw.githubusercontent.comreact.devreactjs.orgregistry.opendata.awsrepost.awsrequests.readthedocs.iorich.readthedocs.iorightfootin.blogspot.comroadmap.streamlit.approlldown.rss3-us-west-2.amazonaws.coms3.console.aws.amazon.coms3tables.us-west-2.amazonaws.comschema.orgsdk.amazonaws.comserverfault.comservice.ecs.region.on.awsservicereference.us-east-1.amazonaws.comsethmlarson.devsetuptools.readthedocs.iosfu-db.github.ioshare-demo.streamlit.ioshare-head.streamlit.ioshare-staging.streamlit.ioshare.streamlit.iosome.hostnamesourceforge.netspark.apache.orgspdx.devsqlglot.comstackoverflow.comstarlette.devstates-language.netstatic.streamlit.iostorage.azure.comstorage.googleapis.comstrandsagents.comstreamlit-demo-data.s3-us-west-2.amazonaws.comstreamlit.iosupport.microsoft.comsupport.orcid.orgsvrintl-g3-aia.verisign.comsvrintl-g3-crl.verisign.comswagger.iotestca.pythontest.nettimeapi.iotoml.iotools.ietf.orgtrino.iotruststore.pki.rds.amazonaws.comturbopuffer.comtwistedmatrix.comtwitter.comtyper.tiangolo.comunpkg.comupload.wikimedia.orgurllib3.readthedocs.ious-east-1.console.aws.amazon.comus-west-2-1.aws.cloud2.influxdata.comuse.typekit.netvalkey-io.github.iovalkey.iovega.github.iovisjs.github.iovote.comw3id.orgweb.archive.orgwebsockets.readthedocs.iowheel.readthedocs.iowiki.centos.orgwiki.openstreetmap.orgwww.apache.orgwww.cacert.orgwww.cl.cam.ac.ukwww.commonwl.orgwww.cracker.comwww.crummy.comwww.databricks.comwww.datastax.comwww.dnspython.orgwww.egenix.comwww.example.珠宝www.extremelycoolapp.comwww.freebsd.orgwww.freetds.orgwww.gevent.orgwww.github.comwww.gmarts.orgwww.gnu.orgwww.google.comwww.googleapis.comwww.gossamer-threads.comwww.gzip.orgwww.iana.orgwww.json.orgwww.libreoffice.orgwww.linuxprogrammingblog.comwww.mapbox.comwww.microsoft.comwww.mongodb.comwww.openarchives.orgwww.oracle.comwww.oreilly.comwww.pcre.orgwww.perl.orgwww.picloud.comwww.postgresql.orgwww.pyopenssl.orgwww.python.orgwww.rabbitmq.comwww.rfc-editor.orgwww.secg.orgwww.sqlite.orgwww.systutorials.comwww.tondering.dkwww.unicode.orgwww.w3.orgwww.xudongz.comwww.youtube.comxlsxwriter.readthedocs.ioxmfe3hc3pk.execute-api.us-east-2.amazonaws.comxmlns.comxn--fiqs8s.icom.museumxxhash.comyahoo.comyaml.devyaml.orgyoutu.bezopecomponent.readthedocs.io

medium bedrock-agentcore PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcepkgs/python/[email protected]/tests_integ/tools/test_code.py:236
  2. 2sinkpkgs/python/[email protected]/tests_integ/tools/test_code.py:257
medium bedrock-agentcore PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcepkgs/python/[email protected]/tests_integ/tools/test_code.py:236
  2. 2sinkpkgs/python/[email protected]/tests_integ/tools/test_code.py:269
medium bedrock-agentcore PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcepkgs/python/[email protected]/tests_integ/tools/test_code.py:236
  2. 2sinkpkgs/python/[email protected]/tests_integ/tools/test_code.py:310
hub Dependency data flows (1)
medium pyiceberg dependency A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
  1. 1sourcepkgs/python/[email protected]/pyiceberg/io/fsspec.py:102
  2. 2sinkpkgs/python/[email protected]/pyiceberg/io/fsspec.py:113

</> First-Party Code

first-party (python): samples/mcp-integration-with-kb

python first-party

first-party (python): samples/mcp-integration-with-nova-canvas

python first-party
expand_more 4 low-confidence finding(s)
low env_fs Environment-variable access. 3 locations
low env_fs production #8802e4eb4a85aaba capability detected · no path traced Filesystem access.
repo/samples/mcp-integration-with-nova-canvas/user_interfaces/image_generator_st.py:274
                    with open(image_path, 'rb') as file:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/amazon-bedrock-agentcore-mcp-server

python first-party
expand_more 19 low-confidence finding(s)
low env_fs Environment-variable access. 18 locations
low egress production #9d17afc3491c1ca8 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/amazon-bedrock-agentcore-mcp-server/awslabs/amazon_bedrock_agentcore_mcp_server/utils/doc_fetcher.py:60
    with urllib.request.urlopen(req, timeout=doc_config.timeout) as r:  # nosec

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/amazon-mq-mcp-server

python first-party
expand_more 8 low-confidence finding(s)
low env_fs Environment-variable access. 2 locations
low egress production #83d7055cfe757741 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/amazon-mq-mcp-server/awslabs/amazon_mq_mcp_server/rabbitmq/admin.py:41
        response = requests.request(method, url, headers=self.headers, json=data, verify=True)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs Filesystem access. 5 locations

first-party (python): src/amazon-neptune-mcp-server

python first-party

first-party (python): src/amazon-qindex-mcp-server

python first-party

first-party (python): src/amazon-sns-sqs-mcp-server

python first-party

first-party (python): src/amazon-translate-mcp-server

python first-party
expand_more 21 low-confidence finding(s)
low env_fs Environment-variable access. 20 locations
low env_fs production #1c3effd9b8aecce6 capability detected · no path traced Filesystem access.
repo/src/amazon-translate-mcp-server/awslabs/amazon_translate_mcp_server/terminology_manager.py:340
            with open(file_path_obj, 'rb') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/aurora-dsql-mcp-server

python first-party
expand_more 1 low-confidence finding(s)
low egress production #10856498ee31fa5d capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/aurora-dsql-mcp-server/awslabs/aurora_dsql_mcp_server/server.py:731
            response = await client.post(knowledge_server, json=payload)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/aws-api-mcp-server

python first-party
expand_more 25 low-confidence finding(s)
low env_fs Filesystem access. 4 locations
low env_fs Environment-variable access. 18 locations
low egress production #e407eee3b91af26a capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
repo/src/aws-api-mcp-server/awslabs/aws_api_mcp_server/core/metadata/read_only_operations_list.py:54
            response = requests.get(SERVICE_REFERENCE_URL, timeout=DEFAULT_REQUEST_TIMEOUT).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations

first-party (python): src/aws-appsync-mcp-server

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #3e501bbf2908955a capability detected · no path traced Environment-variable access.
repo/src/aws-appsync-mcp-server/awslabs/aws_appsync_mcp_server/helpers.py:33
            profile_name=os.getenv('AWS_PROFILE'), region_name=os.getenv('AWS_REGION', 'us-east-1')

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/aws-for-sap-management-mcp-server

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #f4e22e119daf219d capability detected · no path traced Environment-variable access.
repo/src/aws-for-sap-management-mcp-server/awslabs/aws_for_sap_management_mcp_server/client_factory.py:40
        profile_name = getenv('AWS_PROFILE', None)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/aws-healthomics-mcp-server

python first-party
expand_more 26 low-confidence finding(s)
low env_fs Environment-variable access. 19 locations
low env_fs Filesystem access. 7 locations

first-party (python): src/aws-iac-mcp-server

python first-party
expand_more 7 low-confidence finding(s)
low env_fs Environment-variable access. 6 locations
low env_fs production #244a31386a04cac1 capability detected · no path traced Filesystem access.
repo/src/aws-iac-mcp-server/awslabs/aws_iac_mcp_server/tools/cloudformation_compliance_checker.py:52
        with open(_bundled_rules_path(), 'r') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/aws-iot-sitewise-mcp-server

python first-party

first-party (python): src/aws-network-mcp-server

python first-party

first-party (python): src/aws-serverless-mcp-server

python first-party
expand_more 16 low-confidence finding(s)
low env_fs Environment-variable access. 6 locations
low env_fs Filesystem access. 9 locations
low egress production #87220caf71b3d1bd capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/aws-serverless-mcp-server/awslabs/aws_serverless_mcp_server/utils/github.py:37
        response = requests.get(url, headers=default_headers, timeout=30)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/aws-support-mcp-server

python first-party

first-party (python): src/aws-transform-mcp-server

python first-party
expand_more 20 low-confidence finding(s)
low env_fs Environment-variable access. 11 locations
low env_fs Filesystem access. 4 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations

first-party (python): src/billing-cost-management-mcp-server

python first-party
expand_more 14 low-confidence finding(s)
low env_fs Environment-variable access. 13 locations
low env_fs production #3e22fe54ede5ba8d capability detected · no path traced Filesystem access.
repo/src/billing-cost-management-mcp-server/awslabs/billing_cost_management_mcp_server/tools/recommendation_details_tools.py:434
            with open(template_path, 'r') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/ccapi-mcp-server

python first-party
expand_more 35 low-confidence finding(s)
low env_fs Environment-variable access. 30 locations
low env_fs Filesystem access. 5 locations

first-party (python): src/cloudtrail-mcp-server

python first-party
expand_more 1 low-confidence finding(s)
low env_fs production #231b2a5d77c1c97a capability detected · no path traced Environment-variable access.
repo/src/cloudtrail-mcp-server/awslabs/cloudtrail_mcp_server/tools.py:52
            if aws_profile := os.environ.get('AWS_PROFILE'):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/cloudwatch-applicationsignals-mcp-server

python first-party
expand_more 38 low-confidence finding(s)
low env_fs Environment-variable access. 24 locations
low env_fs Filesystem access. 11 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

first-party (python): src/cloudwatch-mcp-server

python first-party
expand_more 4 low-confidence finding(s)
low env_fs Environment-variable access. 3 locations
low env_fs production #80f92cdb85f40f19 capability detected · no path traced Filesystem access.
repo/src/cloudwatch-mcp-server/awslabs/cloudwatch_mcp_server/cloudwatch_metrics/tools.py:90
            with open(metadata_file, 'r', encoding='utf-8') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/dynamodb-mcp-server

python first-party
expand_more 39 low-confidence finding(s)
low env_fs Filesystem access. 25 locations
low env_fs Environment-variable access. 13 locations
low egress production #029639996d6067df capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/dynamodb-mcp-server/awslabs/dynamodb_mcp_server/model_validation_utils.py:381
        with urllib.request.urlopen(  # nosec B310
            DynamoDBLocalConfig.DOWNLOAD_URL, timeout=DynamoDBLocalConfig.DOWNLOAD_TIMEOUT
        ) as response:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/ecs-mcp-server

python first-party

first-party (python): src/eks-mcp-server

python first-party
expand_more 22 low-confidence finding(s)
low env_fs Environment-variable access. 11 locations
low env_fs Filesystem access. 9 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

first-party (python): src/healthlake-mcp-server

python first-party
expand_more 8 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 7 locations
low env_fs production #e11bfe8aced29ac4 capability detected · no path traced Environment-variable access.
repo/src/healthlake-mcp-server/awslabs/healthlake_mcp_server/main.py:34
logger.add(sys.stderr, level=os.getenv('MCP_LOG_LEVEL', 'WARNING'))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/mcp-lambda-handler

python first-party

first-party (python): src/memcached-mcp-server

python first-party

first-party (python): src/mssql-mcp-server

python first-party
expand_more 2 low-confidence finding(s)
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations

first-party (python): src/mysql-mcp-server

python first-party
expand_more 3 low-confidence finding(s)
low env_fs Filesystem access. 2 locations
low egress production #e06d2e42adb72765 capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
repo/src/mysql-mcp-server/hatch_build.py:100
        with urllib.request.urlopen(  # nosec B310
            _RDS_CA_BUNDLE_URL, timeout=30, context=ctx
        ) as resp:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/openapi-mcp-server

python first-party
expand_more 25 low-confidence finding(s)
low env_fs Environment-variable access. 17 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
low env_fs Filesystem access. 3 locations

first-party (python): src/roda-mcp-server

python first-party
expand_more 3 low-confidence finding(s)
low env_fs production #d123609c096c9154 capability detected · no path traced Environment-variable access.
repo/src/roda-mcp-server/awslabs/roda_mcp_server/server.py:35
logger.add(sys.stderr, level=os.getenv('FASTMCP_LOG_LEVEL', 'WARNING'))

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

first-party (python): src/sagemaker-ai-mcp-server

python first-party
expand_more 5 low-confidence finding(s)
low env_fs Environment-variable access. 4 locations
low env_fs production #fff0d20e22c32d92 capability detected · no path traced Filesystem access.
repo/src/sagemaker-ai-mcp-server/awslabs/sagemaker_ai_mcp_server/sagemaker_hyperpod/hyperpod_stack_handler.py:360
                with open(validated_path, 'r') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

first-party (python): src/valkey-mcp-server

python first-party
expand_more 30 low-confidence finding(s)
low env_fs Environment-variable access. 28 locations
low env_fs production #8a9c67880e6959ab capability detected · no path traced Filesystem access.
repo/src/valkey-mcp-server/awslabs/valkey_mcp_server/common/connection.py:72
            with open(ca_path, 'rb') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress production #83e536431d7ad63c capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
repo/src/valkey-mcp-server/awslabs/valkey_mcp_server/embeddings/providers.py:54
        response = await self._client.post(
            f'{self.base_url}/api/embeddings',
            json={'model': self.model, 'prompt': text},
        )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

first-party (python): src/well-architected-security-mcp-server

python first-party
expand_more 4 low-confidence finding(s)
low env_fs Environment-variable access. 3 locations
low env_fs production #9d4152ec35396c44 capability detected · no path traced Filesystem access.
repo/src/well-architected-security-mcp-server/awslabs/well_architected_security_mcp_server/util/prompt_utils.py:49
        with open(file_path, "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

</> Dependencies

bedrock-agentcore

python dependency
medium telemetry dependency Excluded from app score #eb943e0648676460 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/python/[email protected]/src/bedrock_agentcore/runtime/tracing.py:47
        from opentelemetry import trace

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #bd2def7e1ff49395 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/python/[email protected]/src/bedrock_agentcore/runtime/tracing.py:83
        from opentelemetry.sdk.trace import SpanProcessor  # type: ignore[import]

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium telemetry dependency Excluded from app score #5479dce0cb499c19 capability detected · no path traced Telemetry/analytics SDK usage detected. Confirm user consent and that no PII is sent without a lawful basis.
pkgs/python/[email protected]/src/bedrock_agentcore/runtime/tracing.py:121
                from opentelemetry import baggage as otel_baggage

A telemetry/analytics SDK is used; event data is sent to a third-party collector.

Fix: Ensure user consent and a lawful basis; strip PII from event payloads.

medium pii_flow tooling reachable #15237052b8c5eec7 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
pkgs/python/[email protected]/tests_integ/tools/test_code.py:257 · flow /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 → /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:257
    print(f"  Created interpreter: {interpreter_id}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow tooling reachable #ce77b8c624e37d06 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
pkgs/python/[email protected]/tests_integ/tools/test_code.py:269 · flow /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 → /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:269
    print(f"  Interpreter status: {info['status']}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

medium pii_flow tooling reachable #fe0ace00b26379ce PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
pkgs/python/[email protected]/tests_integ/tools/test_code.py:310 · flow /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:236 → /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/tests_integ/tools/test_code.py:310
    print(f"  Cleaned up interpreter: {interpreter_id}")

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

expand_more 184 low-confidence finding(s)
low env_fs Filesystem access. 20 locations
low env_fs Environment-variable access. 151 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 13 locations

pyiceberg

python dependency
medium pii_flow dependency Excluded from app score #3edb6da5367bd2fa A credential read from the environment/filesystem is applied as authorization on the same outbound request (auth header). This is intentional authentication, not unexpected data exfiltration.
pkgs/python/[email protected]/pyiceberg/io/fsspec.py:113 · flow /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/pyiceberg/io/fsspec.py:102 → /tmp/closeopen-e1f6yq29/pkgs/python/[email protected]/pyiceberg/io/fsspec.py:113
    response = requests.post(f"{signer_url}/{signer_endpoint.strip()}", headers=signer_headers, json=signer_body)

A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.

Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.

expand_more 22 low-confidence finding(s)
low env_fs Environment-variable access. 3 locations
low env_fs Filesystem access. 5 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 14 locations

botocore

python dependency
expand_more 36 low-confidence finding(s)
low env_fs Environment-variable access. 31 locations
low env_fs Filesystem access. 5 locations

cassandra-driver

python dependency
expand_more 4 low-confidence finding(s)
low env_fs dependency Excluded from app score #a5d7c8234868ad6b capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/cassandra/cqlengine/management.py:544
    if not os.getenv(CQLENG_ALLOW_SCHEMA_MANAGEMENT):

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Filesystem access. 2 locations
low egress dependency Excluded from app score #1fcfd63f89c46682 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/cassandra/datastax/cloud/__init__.py:139
        response = urlopen(url, context=config.ssl_context, timeout=timeout)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

cfn-lint

python dependency
expand_more 29 low-confidence finding(s)
low env_fs Environment-variable access. 5 locations
low env_fs Filesystem access. 21 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

coloredlogs

python dependency
expand_more 24 low-confidence finding(s)

cwltool

python dependency
expand_more 87 low-confidence finding(s)
low env_fs Filesystem access. 41 locations
low env_fs Environment-variable access. 43 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

daft

python dependency
expand_more 28 low-confidence finding(s)
low env_fs Environment-variable access. 23 locations
low env_fs Filesystem access. 2 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations

fastapi

python dependency
expand_more 70 low-confidence finding(s)
low env_fs Filesystem access. 55 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 12 locations
low env_fs tooling Excluded from app score unreachable #09a516da41260ade capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/scripts/docs.py:129
    os.environ["DYLD_FALLBACK_LIBRARY_PATH"] = "/opt/homebrew/lib"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

gevent

python dependency
expand_more 996 low-confidence finding(s)
low env_fs Environment-variable access. 265 locations
low env_fs Filesystem access. 446 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 185 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 100 locations

influxdb-client

python dependency
expand_more 26 low-confidence finding(s)
low env_fs Filesystem access. 7 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
low env_fs Environment-variable access. 14 locations

jinja2

python dependency
expand_more 7 low-confidence finding(s)
low env_fs Filesystem access. 6 locations
low egress dependency Excluded from app score #1904ebbe455f304d capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/src/jinja2/bccache.py:390
            code = self.client.get(self.prefix + bucket.key)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

kubernetes

python dependency
expand_more 68 low-confidence finding(s)
low env_fs Filesystem access. 41 locations
low env_fs Environment-variable access. 17 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 10 locations

langchain-mcp-adapters

python dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #a0a93517598181eb capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/langchain_mcp_adapters/sessions.py:45
    return _BRACED_VAR_RE.sub(lambda m: os.environ.get(m.group(1), m.group(0)), value)

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

mcp

python dependency
expand_more 39 low-confidence finding(s)
low env_fs Environment-variable access. 16 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 6 locations
low env_fs Filesystem access. 15 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 2 locations

miniwdl

python dependency
expand_more 54 low-confidence finding(s)
low env_fs Environment-variable access. 23 locations
low env_fs Filesystem access. 31 locations

openai

python dependency
expand_more 69 low-confidence finding(s)
low env_fs Filesystem access. 16 locations
low env_fs Environment-variable access. 47 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
low egress Hardcoded external endpoint. Review what data is sent to this destination. 4 locations

openapi-spec-validator

python dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #24904222806b63ca capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/openapi_spec_validator/__main__.py:74
    return os.getenv("OPENAPI_SPEC_VALIDATOR_WARN_DEPRECATED", "1") != "0"

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

oracledb

python dependency
expand_more 5 low-confidence finding(s)
low env_fs dependency Excluded from app score #bfc737e22ae0a7b8 capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/setup.py:95
extra_compile_args = os.environ.get("PYO_COMPILE_ARGS", "").split()

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Filesystem access. 3 locations
low egress dependency Excluded from app score #e6acd3effd27ab51 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/src/oracledb/plugins/oci_tokens.py:232
    response = requests.post(
        end_user_sec_params.get("authority"), headers=headers, data=payload
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

polars

python dependency
expand_more 93 low-confidence finding(s)
low env_fs Environment-variable access. 89 locations
low env_fs Filesystem access. 3 locations
low egress dependency Excluded from app score #314d6e78af09fd84 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/src/polars/io/_utils.py:321
    with urlopen(path) as f:

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

prance

python dependency
expand_more 6 low-confidence finding(s)
low egress dependency Excluded from app score #0618e34172525f3c capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
pkgs/python/[email protected]/prance/convert.py:46
    r = requests.post(
        "https://converter.swagger.io/api/convert", data=data, headers=headers
    )

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs dependency Excluded from app score #b4842847af2e73ed capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/prance/util/fs.py:69
            os.environ.get("SYSTEMDRIVE", "C:")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

low env_fs Filesystem access. 3 locations
low egress dependency Excluded from app score #e5f73e8c2cf4b68b capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/prance/util/url.py:205
        response = requests.get(url.geturl())

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

prometheus-client

python dependency
expand_more 21 low-confidence finding(s)
low env_fs Environment-variable access. 14 locations
low env_fs Filesystem access. 6 locations
low egress dependency Excluded from app score #42ede0e9d111dc7e capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/prometheus_client/exposition.py:518
        resp = build_opener(base_handler).open(request, timeout=timeout)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

psutil

python dependency
expand_more 28 low-confidence finding(s)
low env_fs Filesystem access. 19 locations
low env_fs Environment-variable access. 7 locations
low egress tooling Excluded from app score unreachable #612218adb49c6e35 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/scripts/internal/find_broken_links.py:194
            res = requests.get(url, timeout=REQUEST_TIMEOUT)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low egress tooling Excluded from app score unreachable #7613b2ae898911db capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
pkgs/python/[email protected]/scripts/internal/install_pip.py:34
        req = urlopen(URL, **kwargs)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

pymemcache

python dependency
expand_more 1 low-confidence finding(s)
low egress dependency Excluded from app score #000fc71f22d2fd84 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/pymemcache/client/base.py:1494
                return client.get(key, default)

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

pymongo

python dependency
expand_more 117 low-confidence finding(s)
low env_fs Filesystem access. 20 locations
low env_fs Environment-variable access. 92 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations

python-dateutil

python dependency
expand_more 9 low-confidence finding(s)
low env_fs Filesystem access. 8 locations
low env_fs dependency Excluded from app score #fcc256b5348c5d80 capability detected · no path traced Environment-variable access.
pkgs/python/[email protected]/src/dateutil/tz/tz.py:1596
                    name = os.environ["TZ"]

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

python-multipart

python dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #ad67826ebfe017a1 capability detected · no path traced Filesystem access.
pkgs/python/[email protected]/python_multipart/multipart.py:516
                tmp_file = open(path, "w+b")

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

pyyaml

python dependency
expand_more 3 low-confidence finding(s)

requests_auth_aws_sigv4

python dependency
expand_more 6 low-confidence finding(s)
low env_fs Environment-variable access. 4 locations
low egress dependency Excluded from app score #5d08c365c97ca011 capability detected · no path traced Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination.
pkgs/python/[email protected]/requests_auth_aws_sigv4/__main__.py:79
    r = requests.request(args.request, args.url, headers=headers, data=post_data,
        auth=AWSSigV4(args.service, region=args.region))

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

low env_fs dependency Excluded from app score #e4bee57fe9e0529e capability detected · no path traced Filesystem access.
pkgs/python/[email protected]/setup.py:5
with open("README.md", "r") as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

sqlglot

python dependency
expand_more 3 low-confidence finding(s)
low env_fs Environment-variable access. 2 locations
low env_fs dependency Excluded from app score #20c0627c2fc8d28a capability detected · no path traced Filesystem access.
pkgs/python/[email protected]/sqlglotc/setup.py:144
            with open(pkg_info, encoding="utf-8") as fd:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

sqlparse

python dependency
expand_more 2 low-confidence finding(s)

streamlit

python dependency
expand_more 56 low-confidence finding(s)
low env_fs Environment-variable access. 19 locations
low env_fs Filesystem access. 32 locations
low egress Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
low egress dependency Excluded from app score #65804a7b42fe00cb capability detected · no path traced Hardcoded external endpoint. Review what data is sent to this destination.
pkgs/python/[email protected]/streamlit/runtime/credentials.py:78
        response_json = requests.get(
            "https://data.streamlit.io/metrics.json", timeout=2
        ).json()

Data is sent to a hardcoded external endpoint; review what leaves the process.

Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.

thefuzz

python dependency
expand_more 1 low-confidence finding(s)
low env_fs dependency Excluded from app score #ed7320f05671471d capability detected · no path traced Filesystem access.
pkgs/python/[email protected]/setup.py:10
with open('README.rst') as f:

Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.

Fix: Usually benign; confirm any secret read here is not later sent externally.

uvicorn

python dependency

Skipped dependencies

Production

  • pillow prod — sdist exceeds byte cap
  • langchain-community prod — sdist exceeds byte cap
  • boto3-stubs prod — no python source in sdist
  • fastmcp prod — sdist exceeds byte cap
  • python-Levenshtein prod — no python source in sdist
  • guardpycfn prod — no python source in sdist
  • playwright prod — no sdist (wheels only)
  • awslabs.mysql-mcp-server prod — scan budget exceeded
  • awslabs-aws-api-mcp-server prod — scan budget exceeded
  • asyncmy prod — scan budget exceeded
  • defusedxml prod — scan budget exceeded
  • starlette prod — scan budget exceeded
  • authlib prod — scan budget exceeded
  • numpy prod — scan budget exceeded
  • pandas prod — scan budget exceeded
  • statsmodels prod — scan budget exceeded
  • PyYAML prod — scan budget exceeded
  • pdfplumber prod — scan budget exceeded
  • markitdown prod — scan budget exceeded
  • pdf2image prod — scan budget exceeded
  • python-json-logger prod — scan budget exceeded
  • setuptools prod — scan budget exceeded
  • importlib_resources prod — scan budget exceeded
  • python-frontmatter prod — scan budget exceeded
  • awscli prod — scan budget exceeded
  • gitignorefile prod — scan budget exceeded
  • idna prod — scan budget exceeded
  • protego prod — scan budget exceeded
  • readabilipy prod — scan budget exceeded
  • dsql-lint prod — scan budget exceeded
  • langdetect prod — scan budget exceeded
  • virtualenv prod — scan budget exceeded
  • checkov prod — scan budget exceeded
  • mypy-boto3-qbusiness prod — scan budget exceeded