photo-clipper
Warn
Audited by Snyk on Feb 16, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill calls the OpenRouter GPT-5 Vision API at https://openrouter.ai/api/v1/chat/completions (via API_URL https://openrouter.ai/api/v1) at runtime to obtain JSON clipping suggestions that are parsed and used directly to control cropping instructions, so this external URL directly controls agent behavior.
Audit Metadata