@2048/backup

Warn

Audited by Snyk on May 8, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill's runtime scripts call the internal storage endpoint http://sc-agent-backup.internal:8080 (e.g., download.py, list.py, delete.py) to fetch backup bundles that include api/profile.json and settings.json which the restore flow applies to agent_profile/user_settings — meaning remote content fetched from that URL can directly change the agent's prompts/identity and is required for restore.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 8, 2026, 03:04 PM
Issues
1