@2048/backup
Warn
Audited by Snyk on May 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's runtime scripts call the internal storage endpoint http://sc-agent-backup.internal:8080 (e.g., download.py, list.py, delete.py) to fetch backup bundles that include api/profile.json and settings.json which the restore flow applies to agent_profile/user_settings — meaning remote content fetched from that URL can directly change the agent's prompts/identity and is required for restore.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata