MEDIUMsrc/auth/oauth.ts:12 — Hardcoded external endpoint 'account.withings.com'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
MEDIUMsrc/auth/oauth.ts:13 — Hardcoded external endpoint 'wbsapi.withings.net'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
MEDIUMsrc/auth/oauth.ts:240 — Hardcoded external endpoint 'datatracker.ietf.org'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
MEDIUMsrc/withings/api.ts:23 — Hardcoded external endpoint 'wbsapi.withings.net'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
MEDIUMsrc/server/app.ts:29 — Hardcoded external endpoint 'internal-hostname'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
MEDIUMsrc/server/app.ts:182 — Hardcoded external endpoint 'www.googletagmanager.com'. STATIC signal only: this flags a declared destination for human or dynamic-egress confirmation; it does NOT assert exfiltration.
+ 2 more in this check