1password
Warn
Audited by Snyk on Mar 3, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill uses 1Password runtime URLs (e.g., op://app-prod/db/password and op://app-prod/ssh key/private key) which are fetched at runtime and can be injected via
op injector placed into env and executed viaop run, so external content from those URLs can directly control prompts or execution.
Audit Metadata