og-image-design
Warn
Audited by Snyk on Mar 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly requires the inference.sh CLI and includes runtime commands like "infsh app run infsh/html-to-image" and "infsh app run falai/flux-dev-lora" that call https://inference.sh to execute remote apps/models and supply prompts, so the external service (https://inference.sh / infsh/* apps) is a required runtime dependency that executes code and processes prompt input.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata