ace-step

Warn

Audited by Snyk on Aug 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The inpaint/outpaint routes require user-supplied HTTPS audio URLs that the CLI/API fetches at runtime (e.g., https://your-cdn.example/original-track.mp3), and the skill itself warns that embedded/steganographic content in those fetched audio files can directly influence model generation (indirect prompt injection).

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 13, 2026, 10:56 AM
Issues
1
Security Audit — snyk — ace-step