Close Open Privacy Scan
App Privacy Score
Low risk · 360 finding(s)
Dependency score: 22 (High risk)
bar_chart Score Breakdown
list Scan Summary
swap_horiz Application data flows
No application data flows were found. See dependency data flows below.
hub Dependency data flows (130)
pkgs/go/[email protected]/examples/buttons/buttons.go:15 → pkgs/go/[email protected]/examples/buttons/buttons.go:51pkgs/go/[email protected]/examples/buttons/buttons.go:15 → pkgs/go/[email protected]/examples/buttons/buttons.go:53pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:41pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:42pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:47pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:50pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:53pkgs/go/[email protected]/examples/connparams/connparams.go:13 → pkgs/go/[email protected]/examples/connparams/connparams.go:56pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:24pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:28pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:26pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:30pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:47pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:61pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:66pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:77pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:80pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:88pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:93pkgs/go/[email protected]/examples/socketmode/socketmode.go:16 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:114pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:33pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:34pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:39pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:42pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:45pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:48pkgs/go/[email protected]/examples/websocket/websocket.go:12 → pkgs/go/[email protected]/examples/websocket/websocket.go:51pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:54pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:56pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:62pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:63pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:64pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:67pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:70pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:73pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:75pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:77pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:79pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:81pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:83pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:88pkgs/go/[email protected]/examples/audit/audit.go:25 → pkgs/go/[email protected]/examples/audit/audit.go:91pkgs/go/[email protected]/examples/buttons/buttons.go:18 → pkgs/go/[email protected]/examples/buttons/buttons.go:55pkgs/go/[email protected]/examples/buttons/buttons.go:18 → pkgs/go/[email protected]/examples/buttons/buttons.go:58pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:64pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:65pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:70pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:73pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:76pkgs/go/[email protected]/examples/connparams/connparams.go:20 → pkgs/go/[email protected]/examples/connparams/connparams.go:79pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:18 → pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:36pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:18 → pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:41pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:18 → pkgs/go/[email protected]/examples/conversation_history/conversation_history.go:43pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:24pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:34pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:37pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:39pkgs/go/[email protected]/examples/conversations/conversations.go:11 → pkgs/go/[email protected]/examples/conversations/conversations.go:40pkgs/go/[email protected]/examples/files/files.go:12 → pkgs/go/[email protected]/examples/files/files.go:30pkgs/go/[email protected]/examples/files/files.go:12 → pkgs/go/[email protected]/examples/files/files.go:33pkgs/go/[email protected]/examples/files/files.go:12 → pkgs/go/[email protected]/examples/files/files.go:37pkgs/go/[email protected]/examples/files/files.go:12 → pkgs/go/[email protected]/examples/files/files.go:40pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:12 → pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:47pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:12 → pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:54pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:12 → pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:62pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:12 → pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:77pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:12 → pkgs/go/[email protected]/examples/files/multiple_files/multiple_files.go:81pkgs/go/[email protected]/examples/files_remote/files_remote.go:13 → pkgs/go/[email protected]/examples/files_remote/files_remote.go:27pkgs/go/[email protected]/examples/files_remote/files_remote.go:13 → pkgs/go/[email protected]/examples/files_remote/files_remote.go:30pkgs/go/[email protected]/examples/files_remote/files_remote.go:13 → pkgs/go/[email protected]/examples/files_remote/files_remote.go:34pkgs/go/[email protected]/examples/files_remote/files_remote.go:13 → pkgs/go/[email protected]/examples/files_remote/files_remote.go:37pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:39pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:43pkgs/go/[email protected]/examples/function/function.go:14 → pkgs/go/[email protected]/examples/function/function.go:60pkgs/go/[email protected]/examples/messages/messages.go:16 → pkgs/go/[email protected]/examples/messages/messages.go:50pkgs/go/[email protected]/examples/messages/messages.go:16 → pkgs/go/[email protected]/examples/messages/messages.go:53pkgs/go/[email protected]/examples/modal/modal.go:92 → pkgs/go/[email protected]/examples/modal/modal.go:100pkgs/go/[email protected]/examples/modal/modal.go:92 → pkgs/go/[email protected]/examples/modal/modal.go:114pkgs/go/[email protected]/examples/pagination/pagination.go:53 → pkgs/go/[email protected]/examples/pagination/pagination.go:66pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:35pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:62pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:72pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:78pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:83pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:92pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:99pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:103pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:105pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:111pkgs/go/[email protected]/examples/pins/pins.go:17 → pkgs/go/[email protected]/examples/pins/pins.go:116pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:33pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:41pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:46pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:53pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:57pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:63pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:70pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:74pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:76pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:85pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:87pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:92pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:94pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:96pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:103pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:110pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:114pkgs/go/[email protected]/examples/reactions/reactions.go:17 → pkgs/go/[email protected]/examples/reactions/reactions.go:116pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:62pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:67pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:78pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:81pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:89pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:94pkgs/go/[email protected]/examples/socketmode/socketmode.go:15 → pkgs/go/[email protected]/examples/socketmode/socketmode.go:115pkgs/go/[email protected]/examples/team/team.go:16 → pkgs/go/[email protected]/examples/team/team.go:28pkgs/go/[email protected]/examples/team/team.go:16 → pkgs/go/[email protected]/examples/team/team.go:31pkgs/go/[email protected]/examples/team/team.go:16 → pkgs/go/[email protected]/examples/team/team.go:36pkgs/go/[email protected]/examples/team/team.go:16 → pkgs/go/[email protected]/examples/team/team.go:40pkgs/go/[email protected]/examples/users/users.go:16 → pkgs/go/[email protected]/examples/users/users.go:31pkgs/go/[email protected]/examples/users/users.go:16 → pkgs/go/[email protected]/examples/users/users.go:34pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:44pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:45pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:50pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:53pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:56pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:59pkgs/go/[email protected]/examples/websocket/websocket.go:17 → pkgs/go/[email protected]/examples/websocket/websocket.go:62pkgs/go/[email protected]/examples/oauth_client/main.go:31 → pkgs/go/[email protected]/examples/oauth_client/main.go:89pkgs/go/[email protected]/examples/oauth_client/main.go:31 → pkgs/go/[email protected]/examples/oauth_client/main.go:102</> First-Party Code
first-party (go)
go first-partyexpand_more 62 low-confidence finding(s)
enabledToolsFlag = os.Getenv("SLACK_MCP_ENABLED_TOOLS")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
addMessageToolEnv := os.Getenv("SLACK_MCP_ADD_MESSAGE_TOOL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
host := os.Getenv("SLACK_MCP_HOST")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
port := os.Getenv("SLACK_MCP_PORT")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
host := os.Getenv("SLACK_MCP_HOST")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
port := os.Getenv("SLACK_MCP_PORT")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_XOXP_TOKEN") == "demo" || (os.Getenv("SLACK_MCP_XOXC_TOKEN") == "demo" && os.Getenv("SLACK_MCP_XOXD_TOKEN") == "demo") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_XOXP_TOKEN") == "demo" || (os.Getenv("SLACK_MCP_XOXC_TOKEN") == "demo" && os.Getenv("SLACK_MCP_XOXD_TOKEN") == "demo") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if envLevel := os.Getenv("SLACK_MCP_LOG_LEVEL"); envLevel != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if format := os.Getenv("SLACK_MCP_LOG_FORMAT"); format != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env := os.Getenv("ENVIRONMENT"); env != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("KUBERNETES_SERVICE_HOST") != "" ||
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
os.Getenv("DOCKER_CONTAINER") != "" ||
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
os.Getenv("container") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if colorEnv := os.Getenv("SLACK_MCP_LOG_COLOR"); colorEnv != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("NO_COLOR") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("FORCE_COLOR") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if env := os.Getenv("ENVIRONMENT"); env == "development" || env == "dev" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
unfurlOpt := os.Getenv("SLACK_MCP_ADD_MESSAGE_UNFURLING")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
toolConfig := os.Getenv("SLACK_MCP_ADD_MESSAGE_MARK")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return isChannelAllowedForConfig(channel, os.Getenv("SLACK_MCP_ADD_MESSAGE_TOOL"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
toolConfig := os.Getenv("SLACK_MCP_ADD_MESSAGE_TOOL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
enabledTools := os.Getenv("SLACK_MCP_ENABLED_TOOLS")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
toolConfig := os.Getenv("SLACK_MCP_REACTION_TOOL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
enabledTools := os.Getenv("SLACK_MCP_ENABLED_TOOLS")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
toolConfig := os.Getenv("SLACK_MCP_ATTACHMENT_TOOL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
enabledTools := os.Getenv("SLACK_MCP_ENABLED_TOOLS")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
toolConfig := os.Getenv("SLACK_MCP_MARK_TOOL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
ttlStr := os.Getenv("SLACK_MCP_CACHE_TTL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
intervalStr := os.Getenv("SLACK_MCP_MIN_REFRESH_INTERVAL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxpToken := os.Getenv("SLACK_MCP_XOXP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxcToken := os.Getenv("SLACK_MCP_XOXC_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxdToken := os.Getenv("SLACK_MCP_XOXD_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_GOVSLACK") == "true" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_GOVSLACK") == "true" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_XOXP_TOKEN") == "demo" || (os.Getenv("SLACK_MCP_XOXC_TOKEN") == "demo" && os.Getenv("SLACK_MCP_XOXD_TOKEN") == "demo") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxpToken := os.Getenv("SLACK_MCP_XOXP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxbToken := os.Getenv("SLACK_MCP_XOXB_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxcToken := os.Getenv("SLACK_MCP_XOXC_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
xoxdToken := os.Getenv("SLACK_MCP_XOXD_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
usersCache := os.Getenv("SLACK_MCP_USERS_CACHE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
channelsCache := os.Getenv("SLACK_MCP_CHANNELS_CACHE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_XOXP_TOKEN") == "demo" || (os.Getenv("SLACK_MCP_XOXC_TOKEN") == "demo" && os.Getenv("SLACK_MCP_XOXD_TOKEN") == "demo") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
usersCache := os.Getenv("SLACK_MCP_USERS_CACHE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
channelsCache := os.Getenv("SLACK_MCP_CHANNELS_CACHE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_XOXP_TOKEN") == "demo" || (os.Getenv("SLACK_MCP_XOXC_TOKEN") == "demo" && os.Getenv("SLACK_MCP_XOXD_TOKEN") == "demo") {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if data, err := os.ReadFile(ap.usersCachePath); err == nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if data, err := os.ReadFile(ap.channelsCachePath); err == nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_GOVSLACK") == "true" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tape, err := os.Create("tape.txt")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
keyA := os.Getenv("SLACK_MCP_API_KEY")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
keyA = os.Getenv("SLACK_MCP_SSE_API_KEY")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Getenv(envVarName) != ""
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_PROXY") != "" && os.Getenv("SLACK_MCP_CUSTOM_TLS") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if proxyURL := os.Getenv("SLACK_MCP_PROXY"); proxyURL != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if isToolkit := os.Getenv("SLACK_MCP_SERVER_CA_TOOLKIT"); isToolkit != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if localCertFile := os.Getenv("SLACK_MCP_SERVER_CA"); localCertFile != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
certs, err := ioutil.ReadFile(localCertFile)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_MCP_SERVER_CA_INSECURE") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if localCertFile := os.Getenv("SLACK_MCP_SERVER_CA"); localCertFile != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if ua := os.Getenv("SLACK_MCP_USER_AGENT"); ua != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if useCustomTLS := os.Getenv("SLACK_MCP_CUSTOM_TLS"); useCustomTLS != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
</> Dependencies
github.com/slack-go/slack
go dependency fmt.Printf("Found %d audit log entries (limited to 10)\n", len(entries))
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("More entries available (cursor: %s)\n", nextCursor)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Entry %d: %s\n", i+1, entry.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Action: %s\n", entry.Action)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Date: %s\n", time.Unix(int64(entry.DateCreate), 0).Format(time.RFC3339))
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Actor: %s (%s)\n", entry.Actor.User.Name, entry.Actor.User.Email)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity Type: %s\n", entry.Entity.Type)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: %s (%s)\n", entry.Entity.User.Name, entry.Entity.User.Email)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: #%s (%s)\n", entry.Entity.Channel.Name, entry.Entity.Channel.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: %s (%s)\n", entry.Entity.File.Name, entry.Entity.File.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: %s (%s)\n", entry.Entity.App.Name, entry.Entity.App.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: %s (%s)\n", entry.Entity.Workspace.Name, entry.Entity.Workspace.Domain)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Entity: %s (%s)\n", entry.Entity.Enterprise.Name, entry.Entity.Enterprise.Domain)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" Location: %s (%s)\n", entry.Context.Location.Name, entry.Context.Location.Type)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" IP Address: %s\n", entry.Context.IPAddress)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Could not send message: %v\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message with buttons successfully sent to channel %s at %s", respChannelID, timestamp)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Infos:", ev.Info)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Connection counter:", ev.ConnectionCount)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Presence Change: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Current latency: %v\n", ev.Value)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error: %s\n", ev.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %s\n", message.Attachments[0].Color)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %s\n", message.Text)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error getting info for channel %s: %s\n", channel.ID, err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Channel: %s\n", channel.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Canvas: %+v\n", info.Properties.Canvas)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Tabs: %+v\n", info.Properties.Tabs)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("ID: %s, title: %s\n", file.ID, file.Title)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("File %s deleted successfully.\n", file.ID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Uploading file %s to %s\n", file.Filename, uploads[i].UploadURL)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Files uploaded successfully: %+v\n", c.Files)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Name: %s, URL: %s\n", file.Name, file.URLPrivate)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("File %s deleted successfully.\n", file.Name)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Event received: %+v\n", eventsAPIEvent)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("failed posting message: %v \n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message successfully sent to channel %s at %s", respChannelID, timestamp)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println(err.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println(err.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Collected %d UIDs\n", len(uids))
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error getting channels: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Could not unarchive %s: %s\n", archivedChannel.ID, err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error setting test channel for pinning: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Posting as %s (%s) in channel %s\n", postAsUserName, postAsUserID, postToChannelID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error posting message: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error adding pin: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error listing pins: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("All pins by %s...\n", authTest.User)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" > Item type: %s\n", item.Type)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error remove pin: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error archiving channel: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error getting channels: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Posting as %s (%s) in channel %s\n", postAsUserName, postAsUserID, *channelID)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error posting message: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Adding reaction to message with reference %v\n", msgRef)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error adding reaction: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error adding reaction: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error getting reactions: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%d reactions to message...\n", len(msgReactionsResp.Reactions))
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" %d users say %s in channel %s\n", r.Count, r.Name, msgReactionsResp.Item.Channel)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error listing reactions: %v\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" ResponseMetadata.Messages: %v\n", slackErr.ResponseMetadata.Messages)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("All reactions by %s...\n", authTest.User)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%d on a %s...\n", len(item.Reactions), item.Type)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" %s (along with %d others)\n", r.Name, r.Count-1)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error remove reaction: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error getting reactions: %s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%d reactions to message after removing cry...\n", len(msgReactionsResp.Reactions))
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf(" %d users say %s\n", r.Count, r.Name)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Event received: %+v\n", eventsAPIEvent)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("failed posting message: %v", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("user %q joined to channel %q", ev.User, ev.Channel)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Interaction received: %+v\n", callback)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("ID: %s, BillingActive: %v\n\n\n", *userID, billingActive[*userID])
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("ID: %v, BillingActive: %v\n", id, value)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("ID: %s, Fullname: %s, Email: %s\n", user.ID, user.Profile.RealName, user.Profile.Email)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Infos:", ev.Info)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Connection counter:", ev.ConnectionCount)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Presence Change: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Current latency: %v\n", ev.Value)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Desktop Notification: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error: %s\n", ev.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 38 low-confidence finding(s)
token := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
teamID = os.Getenv("SLACK_TEAM_ID")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
userToken := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
userToken := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
signingSecret = os.Getenv("SLACK_SIGNING_SECRET")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
signingSecret := os.Getenv("SLACK_SIGNING_SECRET")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token, ok := os.LookupEnv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
signingSecret := os.Getenv("SLACK_SIGNING_SECRET")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
apiToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
apiToken := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
r, err := os.Open("slack-go.png")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
signingSecret := os.Getenv("SLACK_SIGNING_SECRET")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
userToken := os.Getenv("SLACK_USER_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
file, err := os.Open(fullpath)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/rusq/slack
go dependency fmt.Printf("Could not send message: %v", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message with buttons successfully sent to channel %s at %s", channelID, timestamp)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Infos:", ev.Info)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Connection counter:", ev.ConnectionCount)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Presence Change: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Current latency: %v\n", ev.Value)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error: %s\n", ev.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("%s\n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Channel: %v\n", channel)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Event received: %+v\n", eventsAPIEvent)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("failed posting message: %v \n", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Event received: %+v\n", eventsAPIEvent)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("failed posting message: %v", err)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("user %q joined to channel %q", ev.User, ev.Channel)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Interaction received: %+v\n", callback)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Ignored %+v\n", evt)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Infos:", ev.Info)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Println("Connection counter:", ev.ConnectionCount)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Message: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Presence Change: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Current latency: %v\n", ev.Value)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Desktop Notification: %v\n", ev)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("Error: %s\n", ev.Error())
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 14 low-confidence finding(s)
token, ok = os.LookupEnv("SLACK_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
channel, ok = os.LookupEnv("SLACK_CHANNEL")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token, ok := os.LookupEnv("SLACK_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
signingSecret := os.Getenv("SLACK_SIGNING_SECRET")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
os.Getenv("SLACK_BOT_TOKEN"),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
slack.OptionAppLevelToken(os.Getenv("SLACK_APP_TOKEN")),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
r, err := os.Open("slack-go.png")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
appToken := os.Getenv("SLACK_APP_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
botToken := os.Getenv("SLACK_BOT_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
token, ok := os.LookupEnv("SLACK_TOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
file, err := os.Open(fullpath)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/mark3labs/mcp-go
go dependency fmt.Printf("Client initialized successfully! Server: %s %s\n",
result.ServerInfo.Name,
result.ServerInfo.Version)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
fmt.Printf("- %s\n", resource.URI)
PII-bearing data is written to a log/print sink — it stays in-process and does not leave the application, but logged PII is still a privacy concern.
Fix: Avoid logging user identifiers; redact or omit PII from log/print statements.
expand_more 7 low-confidence finding(s)
cmd.Env = append(os.Environ(), c.env...)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return withAuthKey(ctx, os.Getenv("API_KEY"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
req, err := http.NewRequestWithContext(ctx, "GET", "https://httpbin.org/anything", nil)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
ClientID: os.Getenv("MCP_CLIENT_ID"),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
ClientSecret: os.Getenv("MCP_CLIENT_SECRET"),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
processedContent, err := os.ReadFile(tempFilePath)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
destFile, err := os.Create(filepath.Join(destPath, fileName))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/gocarina/gocsv
go dependencyexpand_more 1 low-confidence finding(s)
clientsFile, err := os.OpenFile("clients.csv", os.O_RDWR|os.O_CREATE|os.O_TRUNC, os.ModePerm)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/openai/openai-go
go dependencyexpand_more 6 low-confidence finding(s)
if o, ok := os.LookupEnv("OPENAI_BASE_URL"); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if o, ok := os.LookupEnv("OPENAI_API_KEY"); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if o, ok := os.LookupEnv("OPENAI_ORG_ID"); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if o, ok := os.LookupEnv("OPENAI_PROJECT_ID"); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if o, ok := os.LookupEnv("OPENAI_WEBHOOK_SECRET"); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if str, ok := os.LookupEnv(SKIP_MOCK_TESTS); ok {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/refraction-networking/utls
go dependencyexpand_more 12 low-confidence finding(s)
klw, err := os.OpenFile("./sslkeylogging.log", os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0600)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
certOut, err := os.Create("cert.pem")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
keyOut, err := os.OpenFile("key.pem", os.O_WRONLY|os.O_CREATE|os.O_TRUNC, 0600)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Getenv("GO_BUILDER_NAME")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("GO_GCFLAGS") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("GO_GCFLAGS") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
os.Getenv(envVar)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if v, _ := strconv.ParseBool(os.Getenv("GO_BUILDER_FLAKY_NET")); v {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
for _, env := range os.Environ() {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if s := os.Getenv("GO_TEST_TIMEOUT_SCALE"); s != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
certPEMBlock, err := os.ReadFile(certFile)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
keyPEMBlock, err := os.ReadFile(keyFile)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/rusq/slackauth
go dependencyexpand_more 7 low-confidence finding(s)
LocalBrowser{p.Name, filepath.Join(os.Getenv("ProgramFiles"), p.Path)},
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
LocalBrowser{p.Name, filepath.Join(os.Getenv("ProgramFiles(x86)"), p.Path)},
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
LocalBrowser{p.Name, filepath.Join(os.Getenv("LocalAppData"), p.Path)},
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
isDebug = flag.Bool("d", os.Getenv("DEBUG") == "1", "enable debug")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(*traceFile)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
req, err := http.NewRequestWithContext(ctx, http.MethodPost, "https://slack.com/api/auth.test", strings.NewReader(values.Encode()))
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
v := os.Getenv(env)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
github.com/rusq/slackdump/v3
go dependencyexpand_more 51 low-confidence finding(s)
lf, err := os.OpenFile(filename, os.O_CREATE|os.O_APPEND|os.O_WRONLY, 0o666)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
enableLogColors(os.Getenv("NOCOLOR"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs.StringVar(&TraceFile, "trace", os.Getenv("TRACE_FILE"), "trace `filename`")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs.StringVar(&LogFile, "log", os.Getenv("LOG_FILE"), "log `file`, if not specified, messages are printed to STDERR")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs.StringVar(&CPUProfile, "cpuprofile", os.Getenv("CPU_PROFILE"), "write CPU profile to `file`")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
fs.StringVar(&MEMProfile, "memprofile", os.Getenv("MEM_PROFILE"), "write memory profile to `file`")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
in, err = os.Open(args[0])
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
out, err = os.Create(args[1])
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(archive)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(zipfile)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
inf.IsXactive = os.Getenv("DISPLAY") != ""
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
in, err = os.Open(obfparam.input)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
out, err = os.Create(obfparam.output)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filepath)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(args[0])
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(input)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
logf, err := os.Create(logname)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("SLACK_TOKEN") != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(path)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(path)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
var isWSL = os.Getenv("WSL_DISTRO_NAME") != ""
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Create(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filepath.Join(m.dir, currentWspFile))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(filepath.Join(m.dir, currentWspFile))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.OpenFile(filename, os.O_CREATE|os.O_WRONLY, 0o644)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
r, err := os.Open(wf.Name() + extIdx)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
w, err := os.Create(wf.Name() + extIdx)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.Open(filepath.Join(d.dir, UploadsDir, id, name))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(tempfile) // existing temporary file
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
cf, err := os.Open(name)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(src)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
w, err := os.Create(filepath.Join(trgDir, string(fileid)+".json.gz"))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
tape, err := os.Create("tape.txt")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile(path, []byte(content), 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile(filename, []byte("dummy"), 0600); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
var InCI = os.Getenv("CI") == "true"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
in, err := os.Open(src)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return term.IsTerminal(int(os.Stdout.Fd())) && term.IsTerminal(int(os.Stdin.Fd())) && os.Getenv("TERM") != "dumb"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filename)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
var debug = os.Getenv("DEBUG") != ""
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
go.uber.org/zap
go dependencyexpand_more 1 low-confidence finding(s)
if v := os.Getenv("TEST_TIMEOUT_SCALE"); v != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
golang.ngrok.com/ngrok/v2
go dependencyexpand_more 3 low-confidence finding(s)
WithAuthtoken(os.Getenv("NGROK_AUTHTOKEN")),
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if os.Getenv("NGROK_TEST_ONLINE") == "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
authToken := os.Getenv("NGROK_AUTHTOKEN")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
golang.org/x/net
go dependencyexpand_more 28 low-confidence finding(s)
if err := os.WriteFile(name, b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
CGI: os.Getenv("REQUEST_METHOD") != "",
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if val := os.Getenv(n); val != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
var DebugGoroutines = os.Getenv("DEBUG_HTTP2_GOROUTINES") == "1"
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
e := os.Getenv("GODEBUG")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile(name, b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
e := os.Getenv("GODEBUG")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile("const.go", b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if keylog := os.Getenv("SSLKEYLOGFILE"); keylog != "" {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Create(keylog)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
testcase := os.Getenv("TESTCASE")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(filepath.Join(*root, string(req)))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
file, err := os.Create(filepath.Join(*output, u.Path[1:]))
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(defs)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile(zsys, b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile("iana.go", b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.Open(defs)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile(zsys, b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile("iana.go", b, 0644); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
e.val = os.Getenv(n)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
return os.WriteFile(filename, b, 0644)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
res, err := http.Get(gitCommitURL)
Data is sent to a hardcoded external endpoint; review what leaves the process.
Fix: Verify the destination and that only non-sensitive data is sent; pin and audit the dependency.
if err := os.WriteFile("data/text", []byte(combinedText), 0666); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile("data/nodes", nodes, 0666); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
if err := os.WriteFile("data/children", children, 0666); err != nil {
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
s := os.Getenv("GODEBUG")
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
w, err = os.OpenFile(filepath.Join(opts.Dir, filename), os.O_CREATE|os.O_EXCL|os.O_WRONLY, 0666)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.
f, err := os.OpenFile(name, flag, perm)
Reads environment variables or the filesystem — an inventory-level capability, not a leak on its own.
Fix: Usually benign; confirm any secret read here is not later sent externally.