agent-inbox

Fail

Audited by Snyk on Mar 17, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The code deliberately implements auto-spawned headless agents, runs arbitrary shell verification commands supplied in messages, and sends full message/context payloads to configurable webhooks (with environment flags to disable safety checks), creating clear and high-risk vectors for remote code execution and data exfiltration if untrusted messages, webhook URLs, or model/CLI mappings are introduced.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 17, 2026, 06:34 AM
Issues
2
Security Audit — snyk — agent-inbox