Close Open Privacy Scan

bolt Snapshot: commit 21dc4a2
science engine v1.23
schedule 2026-07-25T05:14:30.284305+00:00

verified_user No application data leak found

No high-confidence exfiltration was found in application code. Dependency data flows are listed separately and do not affect this verdict.

smart_toy MCP server detected: @modelcontextprotocol/sdk, openai — detected in dependencies, not a safety judgment.

App Privacy Score

97 /100
Low privacy risk

Low risk · 39 finding(s)

Based on: 8 first-party package(s) · 178/198 deps analyzed

Dependency score: 82 (Low risk)

bar_chart Score Breakdown

env_fs −3

list Scan Summary

0 high 1 medium 38 low
First-party packages: 1
Dependency packages: 2
Ecosystem: go

swap_horiz Application data flows

No application data flows were found. See dependency data flows below.

hub Dependency data flows (1)
medium google.golang.org/protobuf dependency PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
  1. 1sourcepkgs/go/[email protected]/internal/cmd/generate-protos/main.go:517
  2. 2sinkpkgs/go/[email protected]/internal/cmd/generate-protos/main.go:520

</> First-Party Code

</> Dependencies

google.golang.org/protobuf

go dependency
medium pii_flow dependency Excluded from app score #a373cac50cd105c5 PII-bearing data is written to a log/print sink. Logged PII is a privacy concern even when it does not leave the process.
pkgs/go/[email protected]/internal/cmd/generate-protos/main.go:520 · flow /tmp/closeopen-9gfa9bgp/pkgs/go/[email protected]/internal/cmd/generate-protos/main.go:517 → /tmp/closeopen-9gfa9bgp/pkgs/go/[email protected]/internal/cmd/generate-protos/main.go:520
		fmt.Printf("executing: %v\n%s\n", strings.Join(cmd.Args, " "), out)

PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.

Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.

expand_more 22 low-confidence finding(s)
low env_fs Filesystem access. 16 locations
low env_fs Environment-variable access. 6 locations

Skipped dependencies

Production

  • @keyv/redis prod — dist-only: no readable source
  • @librechat/api prod — registry 404
  • keyv prod — dist-only: no readable source
  • @headlessui/react prod — dist-only: no readable source
  • @marsidev/react-turnstile prod — dist-only: no readable source
  • @mcp-ui/client prod — dist-only: no readable source
  • @react-spring/web prod — dist-only: no readable source
  • match-sorter prod — dist-only: no readable source
  • mermaid prod — dist-only: no readable source
  • react-hook-form prod — dist-only: no readable source
  • react-resizable-panels prod — dist-only: no readable source
  • react-router-dom prod — dist-only: no readable source
  • react-speech-recognition prod — dist-only: no readable source
  • react-textarea-autosize prod — dist-only: no readable source
  • react-virtualized prod — dist-only: no readable source
  • react-vtree prod — dist-only: no readable source
  • swr prod — dist-only: no readable source
  • tailwindcss-radix prod — dist-only: no readable source
  • @langchain/langgraph-checkpoint prod — dist-only: no readable source
  • @langchain/langgraph-checkpoint-mongodb prod — dist-only: no readable source