autofigure

Warn

Audited by Snyk on Apr 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill requires runtime calls to external model services — notably SAM3 via the FAL API (https://fal.ai) for segmentation and auto-download of models from Hugging Face (https://huggingface.co) — which are fetched/used at runtime and execute remote model code or produce model outputs that directly determine the generated DrawIO XML.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 28, 2026, 03:54 PM
Issues
1