moda-api
Warn
Audited by Snyk on Jul 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The docs show runtime server fetches of arbitrary URLs via POST https://api.moda.app/v1/uploads/from-url and POST https://api.moda.app/v1/brand-kits (create-from-URL), and those fetched files / scraped content are injected as task attachments or brand kits (role: "source" / brand styling) which directly influence the design agent's prompts and outputs.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata