scheduler
Warn
Audited by Snyk on Aug 26, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). The scheduler daemon exposes a FastAPI runtime where outsider-authored free text can be read from POST/GET request parameters (e.g.,
/jobs/{name}/runand/jobs/{name}/logs), and those inputs are consumed to select and run/return job data (including log contents) without any LLM-based filtering/safe selection step.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The sanity/start scripts invoke the project tool "uv" (uv sync / uv run) which will fetch and install packages from the lockfile (e.g., the sdist at https://files.pythonhosted.org/packages/07/12/3e4389e5920b4c1763390c6d371162f3784f86f85cd6d6c1bfe68eef14e2/apscheduler-3.11.2.tar.gz), meaning remote code from these URLs can be fetched and executed at runtime.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (medium risk: 0.60). The skill instructs the agent to generate and enable a systemd unit (modifying service configuration) and to register/run arbitrary shell commands as scheduled jobs, which can change the machine's runtime state and act like modifying service files.
Issues (3)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata