alipay-payment-feedback

Warn

Audited by Snyk on Apr 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill's install script calls npm to fetch and install the package @alipay/agent-payment from the npm registry (dist tarball fetched at runtime from URLs like https://registry.npmjs.org/@alipay/agent-payment/-/agent-payment-1.0.0.tgz) and then executes its ./node_modules/.bin/agent-payment install-cli, meaning remote code is downloaded and run and is required for the skill.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 27, 2026, 05:09 AM
Issues
1
Security Audit — snyk — alipay-payment-feedback