image-inpainting
Warn
Audited by Snyk on Aug 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill requires user-provided image and mask URLs (e.g., https://your-cdn.example/street.jpg, https://your-cdn.example/cables-mask.png, https://your-cdn.example/product.jpg, https://your-cdn.example/bg-mask.png, https://your-cdn.example/photo.jpg) that are fetched at runtime and the documentation explicitly warns that embedded instructions in those fetched images/masks can influence the inpainting, so external content can directly control model behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata