desktop-packaging
Warn
Audited by Snyk on Jul 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill config includes runtime update endpoints (e.g., "https://releases.example.com/{{target}}/{{current_version}}" and the electron-updater server layout serving latest.yml) which the app fetches at runtime to determine and download installers/updates (i.e., remote content that controls update behavior and results in executing downloaded binaries), so these are runtime external dependencies that can control code execution.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata