alipay-payment-feedback
Warn
Audited by Snyk on Apr 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's install script calls npm to fetch and install the package @alipay/agent-payment from the npm registry (dist tarball fetched at runtime from URLs like https://registry.npmjs.org/@alipay/agent-payment/-/agent-payment-1.0.0.tgz) and then executes its ./node_modules/.bin/agent-payment install-cli, meaning remote code is downloaded and run and is required for the skill.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata