Close Open Privacy Scan
App Privacy Score
Low risk · 219 finding(s)
Based on: 1 first-party package(s) · 6/7 deps analyzed
Dependency score: 22 (High risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Application data flows
No application data flows were found. See dependency data flows below.
hub Dependency data flows (91)
- 1source
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:16
- 1source
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:36
- 1source
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/answer_example.ts:41
- 1source
pkgs/npm/[email protected]__reposrc/examples/chat_completion.ts:6 - 2sink
pkgs/npm/[email protected]__reposrc/examples/chat_completion.ts:26
- 1source
pkgs/npm/[email protected]__reposrc/examples/get_contents_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/get_contents_example.ts:15
- 1source
pkgs/npm/[email protected]__reposrc/examples/links_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/links_example.ts:14
- 1source
pkgs/npm/[email protected]__reposrc/examples/links_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/links_example.ts:21
- 1source
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:12
- 1source
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:19
- 1source
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:32
- 1source
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/livecrawl_example.ts:33
- 1source
pkgs/npm/[email protected]__reposrc/examples/openai_responses.ts:6 - 2sink
pkgs/npm/[email protected]__reposrc/examples/openai_responses.ts:17
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:17
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:24
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:30
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:31
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:37
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:43
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:44
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:62
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:63
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:4 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_events_example.ts:67
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_task_bulk_example.ts:5 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_task_bulk_example.ts:77
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:5 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:34
- 1source
pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:5 - 2sink
pkgs/npm/[email protected]__reposrc/examples/research_task_stream_example.ts:38
- 1source
pkgs/npm/[email protected]__reposrc/examples/search_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/search_example.ts:11
- 1source
pkgs/npm/[email protected]__reposrc/examples/search_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/search_example.ts:18
- 1source
pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:11
- 1source
pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/search_with_contents.ts:21
- 1source
pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:16
- 1source
pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/streaming_example.ts:19
- 1source
pkgs/npm/[email protected]__reposrc/examples/subpages.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/subpages.ts:19
- 1source
pkgs/npm/[email protected]__reposrc/examples/subpages.ts:3 - 2sink
pkgs/npm/[email protected]__reposrc/examples/subpages.ts:30
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:35
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:41
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:65
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:71
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:16 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/exclude_example.ts:78
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:49
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:50
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:15 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/import_example.ts:68
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:56
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:70
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:76
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:106
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:107
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:108
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:111
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:114
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:118
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:122
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:123
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:125
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:137
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:28 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets/monitors_example.ts:146
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:63
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:64
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:74
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:78
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:80
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:91
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:103
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:107
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:118
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:120
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:128
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:135
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:140
- 1source
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:29 - 2sink
pkgs/npm/[email protected]__reposrc/examples/websets_example.ts:143
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:101
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:103
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:105
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:116
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:117
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:121
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:123
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:145
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:147
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:150
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:171
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:193
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:196
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:200
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:216
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:218
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:240
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_answer_example.ts:248
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:112
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:166
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:213
- 1source
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:11 - 2sink
pkgs/npm/[email protected]__reposrc/examples/zod_research_example.ts:259
</> First-Party Code
first-party (npm)
npm first-partyexpand_more 24 low-confidence finding(s)
low env_fs — Environment-variable access. 23 locations
cached ??= stripFrontmatter(readFileSync(findSkillFile(), "utf8"));
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
exa-js
npm dependency console.log("Answer result:", JSON.stringify(answer, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Answer result:", JSON.stringify(structuredAnswer, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Answer result:", JSON.stringify(answerFromLocation, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chunk);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results:", contentsResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results with links:", JSON.stringify(search, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results with links:", JSON.stringify(contents, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results without livecrawl:", JSON.stringify(contentsWithoutLivecrawl, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Get contents results with livecrawl:", JSON.stringify(contentsWithLivecrawl, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Length of text without livecrawl:", textWithoutLivecrawl.length);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Length of text with livecrawl:", textWithLivecrawl.length);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chunk);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Created research: ${research.researchId}\n`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Status: ${withoutEvents.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Has events array: ${Array.isArray(withoutEvents.events)}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Events count: ${withoutEvents.events?.length ?? 0}\n`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Status: ${withEvents.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Has events array: ${Array.isArray(withEvents.events)}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Events count: ${withEvents.events?.length ?? 0}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Final status: ${finalState.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Total events: ${finalState.events?.length ?? 0}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(finalState.output.content.substring(0, 200) + "...");
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Event:", JSON.stringify(event, undefined, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Created Research ID:", research.researchId);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Research Event:", event);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results:", searchResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Search results with contents:", searchWithContentsResponse.results);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results:",
searchResponse.results.map((it) => it)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results with contents:",
searchWithContentsResponse.results
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nChunk:", chunk.content); // Write partial text as it arrives
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nCitations:", chunk.citations); // Handle citations when they arrive
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Search results with subpages:",
JSON.stringify(search, null, 2)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
"Get contents results with subpages:",
JSON.stringify(contents, null, 2)
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created known companies webset: ${knownCompaniesWebset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nKnown companies (${knownItems.data.length} found):`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created new webset: ${newWebset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nNew companies found (${newItems.data.length} total):`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`\n✓ Successfully excluded ${knownItems.data.length} known companies from search`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` ID: ${createdImport.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status: ${createdImport.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Records processed: ${completedImport.count}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created webset: https://websets.exa.ai/${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Webset found ${itemsResponse.data.length} items`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - ${item.properties.description}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Created monitor: ${monitor.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status: ${monitor.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Next run: ${monitor.nextRunAt || "Not scheduled"}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nMonitors for webset ${webset.id}:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - ${m.id}: ${m.behavior.type} monitor (${m.status})`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nMonitor runs for ${monitor.id}:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` - Run ${run.id}: ${run.status} (${run.type})`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Created: ${run.createdAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Completed: ${run.completedAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`✓ Monitor status updated to: ${updatedMonitor.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`- View your webset at: https://websets.exa.ai/${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webset created with ID: ${webset.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Status: ${webset.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webset processing complete. Status: ${idleWebset.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${items.data.length} items:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`- ${
item.properties.type === "company"
? item.properties.company.name
: "Unknown"
}: ${item.properties.url}`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Retrieved ${allItems.length} items in total`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Enrichment created with ID: ${enrichment.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Expanded Webset has ${expandedWebset.items?.length ?? 0} items`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${events.data.length} recent events:`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`- ${event.type} at ${event.createdAt}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Webhook created with ID: ${webhook.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Found ${attempts.data.length} webhook attempts`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`- ${attempt.eventType} at ${attempt.attemptedAt} (${attempt.successful ? "success" : "failed"})`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(` Status code: ${attempt.responseStatusCode}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Title:", comparison.title);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(comparison.executive_summary);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\nItems Compared:", comparison.items_compared.join(", "));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nRecommended Choice: ${comparison.winner}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Reasoning: ${comparison.reasoning}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(comparison.recommendation);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Topic:", explanation.topic);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(explanation.simple_explanation);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(explanation.technical_details);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Market:", research.market_name);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Market Size:", research.market_size);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Growth Rate:", research.growth_rate);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(research.outlook);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Summary:", comparison.summary);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\nSources: ${response.citations.length} citations`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Created research ${research.researchId}, polling for completion...`
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 37 low-confidence finding(s)
low env_fs — Environment-variable access. 30 locations
low env_fs — Filesystem access. 2 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 5 locations
@modelcontextprotocol/sdk
npm dependencyexpand_more 38 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 22 locations
const response = await fetch(url);
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
writeFileSync(outputPath, fullContent, 'utf-8');
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
low env_fs — Environment-variable access. 14 locations
jose
npm dependencyexpand_more 23 low-confidence finding(s)
low env_fs — Filesystem access. 21 locations
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 2 locations
mcp-handler
npm dependencyexpand_more 5 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
low env_fs — Filesystem access. 2 locations
whoami
npm dependencyexpand_more 1 low-confidence finding(s)
var result = name ? name : process.env.USER;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
Skipped dependencies
Production
- agnost prod — dist-only: no readable source