agent-inbox
Fail
Audited by Snyk on Mar 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 0.90). The code deliberately implements auto-spawned headless agents, runs arbitrary shell verification commands supplied in messages, and sends full message/context payloads to configurable webhooks (with environment flags to disable safety checks), creating clear and high-risk vectors for remote code execution and data exfiltration if untrusted messages, webhook URLs, or model/CLI mappings are introduced.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The repo includes runtime adapters that call external LLM endpoints (e.g., https://api.anthropic.com/v1/messages, https://chatgpt.com/backend-api/codex/responses, and https://generativelanguage.googleapis.com/v1beta/models/{model}:generateContent) which are invoked at runtime to produce model outputs that directly drive agent behavior, making these external URLs required runtime dependencies that control prompts/agent actions.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata