ai-multimodal
Warn
Audited by Snyk on Jun 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill loads remote artifacts at runtime that can execute fetched code — notably the Hugging Face repo referenced via https://huggingface.co/microsoft/Florence-2-large is loaded with trust_remote_code=True (executes repo code), and the Docker image nvcr.io/nvidia/tritonserver:24.03-py3 is pulled/run in the deployment, so these runtime external dependencies can execute remote code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata