ucloud-cli
Warn
Audited by Snyk on Jun 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs downloading the required ucloud CLI binaries at runtime from URLs like https://ucloud-infra.cn-bj.ufileos.com/cli/darwin_{amd64,arm64}/ucloud, https://ucloud-infra.cn-bj.ufileos.com/cli/linux_{amd64,arm64}/ucloud and https://ucloud-infra.cn-bj.ufileos.com/cli/windows_amd64/ucloud.exe (used when the CLI is missing or outdated), which would fetch and install executable code the skill depends on—i.e., a runtime remote code fetch-and-execute dependency.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata