Close Open Privacy Scan
App Privacy Score
Low risk · 1190 finding(s)
Based on: 2 first-party package(s) · 69/70 deps analyzed
Dependency score: 22 (High risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Application data flows
No application data flows were found. See dependency data flows below.
hub Dependency data flows (102)
- 1source
pkgs/npm/@[email protected]__sourcemap/src/edge-config.ts:144 - 2sink
pkgs/npm/@[email protected]__sourcemap/src/edge-config.ts:180
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:30
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:42
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:45
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:51
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:53
- 1source
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_batch_jobs.ts:59
- 1source
pkgs/npm/@[email protected]/examples/src/async_chat_no_streaming.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_chat_no_streaming.ts:15
- 1source
pkgs/npm/@[email protected]/examples/src/async_chat_prediction.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_chat_prediction.ts:33
- 1source
pkgs/npm/@[email protected]/examples/src/async_chat_with_image_no_streaming.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_chat_with_image_no_streaming.ts:27
- 1source
pkgs/npm/@[email protected]/examples/src/async_embeddings.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_embeddings.ts:20
- 1source
pkgs/npm/@[email protected]/examples/src/async_files.ts:6 - 2sink
pkgs/npm/@[email protected]/examples/src/async_files.ts:24
- 1source
pkgs/npm/@[email protected]/examples/src/async_files.ts:6 - 2sink
pkgs/npm/@[email protected]/examples/src/async_files.ts:28
- 1source
pkgs/npm/@[email protected]/examples/src/async_files.ts:6 - 2sink
pkgs/npm/@[email protected]/examples/src/async_files.ts:32
- 1source
pkgs/npm/@[email protected]/examples/src/async_files.ts:6 - 2sink
pkgs/npm/@[email protected]/examples/src/async_files.ts:36
- 1source
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:4 - 2sink
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:127
- 1source
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:4 - 2sink
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:128
- 1source
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:4 - 2sink
pkgs/npm/@[email protected]/examples/src/async_function_calling.ts:147
- 1source
pkgs/npm/@[email protected]/examples/src/async_function_calling_streaming.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_function_calling_streaming.ts:150
- 1source
pkgs/npm/@[email protected]/examples/src/async_function_calling_streaming.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_function_calling_streaming.ts:151
- 1source
pkgs/npm/@[email protected]/examples/src/async_json_format.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_json_format.ts:16
- 1source
pkgs/npm/@[email protected]/examples/src/async_ocr_process_from_file.ts:6 - 2sink
pkgs/npm/@[email protected]/examples/src/async_ocr_process_from_file.ts:33
- 1source
pkgs/npm/@[email protected]/examples/src/async_ocr_process_from_url.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/async_ocr_process_from_url.ts:15
- 1source
pkgs/npm/@[email protected]/examples/src/async_structured_outputs.ts:4 - 2sink
pkgs/npm/@[email protected]/examples/src/async_structured_outputs.ts:52
- 1source
pkgs/npm/@[email protected]/examples/src/async_structured_outputs.ts:4 - 2sink
pkgs/npm/@[email protected]/examples/src/async_structured_outputs.ts:70
- 1source
pkgs/npm/@[email protected]/examples/src/azure/async_chat_no_streaming.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/azure/async_chat_no_streaming.ts:27
- 1source
pkgs/npm/@[email protected]/examples/src/prompt_lifecycle.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/prompt_lifecycle.ts:23
- 1source
pkgs/npm/@[email protected]/examples/src/prompt_lifecycle.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/prompt_lifecycle.ts:38
- 1source
pkgs/npm/@[email protected]/examples/src/realtime_microphone.ts:107 - 2sink
pkgs/npm/@[email protected]/examples/src/realtime_microphone.ts:153
- 1source
pkgs/npm/@[email protected]/examples/src/realtime_transcription.ts:162 - 2sink
pkgs/npm/@[email protected]/examples/src/realtime_transcription.ts:213
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning.ts:35
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning.ts:42
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning.ts:47
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning_multi_turn.ts:14 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning_multi_turn.ts:61
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning_multi_turn.ts:14 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning_multi_turn.ts:74
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning_response_shape.ts:7 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning_response_shape.ts:30
- 1source
pkgs/npm/@[email protected]/examples/src/reasoning_response_shape.ts:7 - 2sink
pkgs/npm/@[email protected]/examples/src/reasoning_response_shape.ts:32
- 1source
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:30
- 1source
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:47
- 1source
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:3 - 2sink
pkgs/npm/@[email protected]/examples/src/skill_lifecycle.ts:50
- 1source
pkgs/npm/@[email protected]/packages/mistralai-azure/examples/chatComplete.example.ts:18 - 2sink
pkgs/npm/@[email protected]/packages/mistralai-azure/examples/chatComplete.example.ts:35
- 1source
pkgs/npm/@[email protected]__reposrc/samples/api_version.js:26 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/api_version.js:33
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:34 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:58
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:34 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:65
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:114 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:134
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:114 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:138
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:114 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:151
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:192 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:216
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:225 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:251
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:261 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:284
- 1source
pkgs/npm/@[email protected]__reposrc/samples/cache.js:261 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/cache.js:291
- 1source
pkgs/npm/@[email protected]__reposrc/samples/chat.js:30 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/chat.js:45
- 1source
pkgs/npm/@[email protected]__reposrc/samples/chat.js:30 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/chat.js:47
- 1source
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:24 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:36
- 1source
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:44 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:66
- 1source
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:74 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/code_execution.js:87
- 1source
pkgs/npm/@[email protected]__reposrc/samples/controlled_generation.js:27 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/controlled_generation.js:56
- 1source
pkgs/npm/@[email protected]__reposrc/samples/controlled_generation.js:64 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/controlled_generation.js:76
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:35 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:45
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:35 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:55
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:65 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:86
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:65 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:96
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:106 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:132
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:106 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:140
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:151 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:178
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:151 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:186
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:198 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:242
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:198 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:250
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:264 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:302
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:264 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:311
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:327 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:335
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:327 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:349
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:358 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:368
- 1source
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:358 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/count_tokens.js:388
- 1source
pkgs/npm/@[email protected]__reposrc/samples/embed.js:24 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/embed.js:31
- 1source
pkgs/npm/@[email protected]__reposrc/samples/embed.js:39 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/embed.js:56
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:31 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:41
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:31 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:69
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:78 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:102
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:78 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:117
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:126 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:133
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:126 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:161
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:170 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:194
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:170 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:209
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:222 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:239
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:220 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:267
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:275 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:281
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:290 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:304
- 1source
pkgs/npm/@[email protected]__reposrc/samples/files.js:314 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/files.js:327
- 1source
pkgs/npm/@[email protected]__reposrc/samples/function_calling.js:61 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/function_calling.js:93
- 1source
pkgs/npm/@[email protected]__reposrc/samples/log_prob.js:24 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/log_prob.js:37
- 1source
pkgs/npm/@[email protected]__reposrc/samples/model_configuration.js:24 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/model_configuration.js:38
- 1source
pkgs/npm/@[email protected]__reposrc/samples/safety_settings.js:28 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/safety_settings.js:50
- 1source
pkgs/npm/@[email protected]__reposrc/samples/safety_settings.js:59 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/safety_settings.js:85
- 1source
pkgs/npm/@[email protected]__reposrc/samples/search_grounding.js:31 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/search_grounding.js:50
- 1source
pkgs/npm/@[email protected]__reposrc/samples/search_grounding.js:61 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/search_grounding.js:75
- 1source
pkgs/npm/@[email protected]__reposrc/samples/system_instruction.js:24 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/system_instruction.js:35
- 1source
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:31 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:37
- 1source
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:64 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:84
- 1source
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:125 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:149
- 1source
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:194 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:214
- 1source
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:223 - 2sink
pkgs/npm/@[email protected]__reposrc/samples/text_generation.js:255
</> First-Party Code
first-party (npm)
npm first-partyexpand_more 49 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 11 locations
low env_fs — Environment-variable access. 37 locations
const response = await fetch("https://openrouter.ai/api/v1/models")
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
first-party (npm): __tests__/playwright-test
npm first-partyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
</> Dependencies
@google/generative-ai
npm dependency console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(cacheResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\n\nmodel: ${result.response.text()}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\n\nmodel: ${result.response.text()}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`\n\nmodel: ${result.response.text()}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(cacheGetResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(item);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("initial cache data:", cacheResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("updated cache data:", cacheUpdateResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(countResult.totalTokens); // 11
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(generateResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(countResult.totalTokens); // 10
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chatResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(countResult.totalTokens); // 265
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(generateResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(countResult.totalTokens); // 265
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(generateResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(countResult.totalTokens); // 302
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(generateResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.totalTokens); // 10
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(generateResult.response.usageMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(resultNoInstructions);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(resultWithInstructions);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(resultNoTools);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(resultWithTools);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.embedding);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.embeddings);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Uploaded file ${uploadResult.file.displayName} as: ${uploadResult.file.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Uploaded file ${uploadResult.file.displayName} as: ${uploadResult.file.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Uploaded file ${uploadResult.file.displayName} as: ${uploadResult.file.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Uploaded file ${uploadResult.file.displayName} as: ${uploadResult.file.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Uploaded file ${uploadResponse.file.displayName} as: ${uploadResponse.file.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`name: ${file.name} | display name: ${file.displayName}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`Retrieved file ${getResponse.displayName} as ${getResponse.uri}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Deleted ${uploadResult.file.displayName}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result2.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.candidates[0].logprobsResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.candidates[0].safetyRatings);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.candidates[0].safetyRatings);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.candidates[0].groundingMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.candidates[0].groundingMetadata);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(text);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result.response.text());
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 156 low-confidence finding(s)
low env_fs — Filesystem access. 35 locations
low env_fs — Environment-variable access. 121 locations
@mistralai/mistralai
npm dependencyconsole.log(`Created job with ID: ${job.id}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Job status: ${job.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Job is done, status ${job.status}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(response.body);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(output);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`Error file ID: ${job.errorFile}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Chat:", chatResponse);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chatResponse.choices[0]?.message.content);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("JSON:", chatResponse.choices[0].message.content);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Embeddings Batch:", embeddingsBatchResponse.data);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(createdFile);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(files);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(retrievedFile);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(deletedFile);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`calling functionName: ${functionName}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`functionParams: ${toolCall.function.arguments}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(response.choices[0].message.content);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`calling functionName: ${functionName}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`functionParams: ${toolCall.function.arguments}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Chat:", chatResponse.choices[0].message.content);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("OCR ", ocrResponse);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("OCR:", ocrResponse);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\n", parsedAccumulatedStream);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("\n", chatResponse.choices[0].message.parsed);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log("Success", chatResult);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`created prompt ${promptId} (v${prompt.version})`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`production -> v${live.version}: ${live.definition?.content}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.error(`\nTranscription error: ${errorMessage}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.error(`Transcription error: ${errorMessage}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(content);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(inner.text);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(chunk.text);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`turn ${i + 1}: prompt=${String(promptTokens).padStart(4)} ` +
`completion=${String(completionTokens).padStart(4)} -> ${finalText(message.content)}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`TOTAL: prompt=${totalPrompt} completion=${totalCompletion} ` +
`(sum ${totalPrompt + totalCompletion})`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`typeof content = ${Array.isArray(content) ? "Array" : typeof content}`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(JSON.stringify(content, null, 2));
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`created skill ${skillId} (v${skill.version}), assets: ${Object.keys(
skill.definition?.assets ?? {},
)}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(`published v${version.version}, moved 'main' to it`);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(
`main -> v${runnable.version}: ${runnable.definition?.description}`,
);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
console.log(result);
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 59 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 18 locations
low env_fs — Environment-variable access. 35 locations
low env_fs — Filesystem access. 6 locations
@vercel/edge-config
npm dependency headers,
A credential (read from the environment/filesystem, or parsed from the request URL) is applied as authorization on the same outbound request. This is intentional authentication to the service the credential belongs to, not unexpected data exfiltration.
Fix: Confirm the destination is the credential's own service; scope the credential and avoid logging it. No action if this is the intended authenticated API call.
expand_more 13 low-confidence finding(s)
low env_fs — Environment-variable access. 9 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
@anthropic-ai/sdk
npm dependencyexpand_more 266 low-confidence finding(s)
low env_fs — Filesystem access. 41 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 222 locations
low env_fs — Environment-variable access. 3 locations
@apidevtools/json-schema-ref-parser
npm dependencyexpand_more 2 low-confidence finding(s)
return await fs.promises.readFile(path);
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
const response = await fetch(u, {
method: "GET",
headers: httpOptions.headers || {},
credentials: httpOptions.withCredentials ? "include" : "same-origin",
redirect: "manual",
signal: controller ? controller.signal : null,
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
@hookform/resolvers
npm dependencyexpand_more 1 low-confidence finding(s)
if (schemaOptions?.context && process.env.NODE_ENV === 'development') {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
@supabase/ssr
npm dependencyexpand_more 1 low-confidence finding(s)
const packageName = process.env.npm_package_name;
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
@supabase/supabase-js
npm dependencyexpand_more 2 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
@xenova/transformers
npm dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 6 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 3 locations
ai
npm dependencyexpand_more 4 low-confidence finding(s)
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 4 locations
class-variance-authority
npm dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Environment-variable access. 3 locations
d3-dsv
npm dependencyexpand_more 12 low-confidence finding(s)
low env_fs — Filesystem access. 12 locations
gpt-tokenizer
npm dependencyexpand_more 24 low-confidence finding(s)
low env_fs — Filesystem access. 22 locations
low env_fs — Environment-variable access. 2 locations
i18next-resources-to-backend
npm dependencyexpand_more 2 low-confidence finding(s)
low env_fs — Filesystem access. 2 locations
mammoth
npm dependencyexpand_more 3 low-confidence finding(s)
low env_fs — Filesystem access. 3 locations
next-pwa
npm dependencyexpand_more 18 low-confidence finding(s)
low env_fs — Filesystem access. 4 locations
low env_fs — Environment-variable access. 12 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 2 locations
next-themes
npm dependencyexpand_more 4 low-confidence finding(s)
openai
npm dependencyexpand_more 369 low-confidence finding(s)
low egress — Hardcoded external endpoint. Review what data is sent to this destination. 6 locations
low env_fs — Environment-variable access. 3 locations
low egress — Outbound request to a variable or assembled URL on a network client. Review what data is sent to this destination. 360 locations
pdf-parse
npm dependencyexpand_more 9 low-confidence finding(s)
low env_fs — Filesystem access. 9 locations
react
npm dependencyexpand_more 14 low-confidence finding(s)
low env_fs — Environment-variable access. 14 locations
react-dom
npm dependencyexpand_more 23 low-confidence finding(s)
low env_fs — Environment-variable access. 23 locations
react-hook-form
npm dependencyexpand_more 12 low-confidence finding(s)
low env_fs — Environment-variable access. 4 locations
low env_fs — Filesystem access. 7 locations
const response = await fetch(String(action), {
method,
headers: {
...headers,
...(encType && encType !== 'multipart/form-data'
? { 'Content-Type': encType }
: {}),
},
body: shouldStringifySubmissionData ? formDataJson : formData,
});
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
react-i18next
npm dependencyexpand_more 1 low-confidence finding(s)
inDevelopment = process.env.NODE_ENV !== 'production';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
react-syntax-highlighter
npm dependencyexpand_more 24 low-confidence finding(s)
low env_fs — Filesystem access. 24 locations
react-textarea-autosize
npm dependencyexpand_more 1 low-confidence finding(s)
const test = process.env.NODE_ENV === 'test';
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
sonner
npm dependencyexpand_more 4 low-confidence finding(s)
Skipped dependencies
Production
- next prod — tarball exceeds byte cap