app-store-screenshots
Warn
Audited by Snyk on Mar 7, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill invokes the inference.sh CLI (https://inference.sh) at runtime (e.g., "infsh app run falai/flux-dev-lora", "infsh app run bytedance/seedream-4-5", "infsh app run google/veo-3-1-fast"), which causes remote models/code hosted by inference.sh to be fetched and executed and thus directly controls runtime behavior; therefore this is a required external runtime dependency executing remote code.
Audit Metadata