ml-research-bootstrap
Warn
Audited by Snyk on Jun 13, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly runs runtime installs like "npx skills add a-green-hand-jack/ml-research-skills" which fetches and installs remote code (the a-green-hand-jack/ml-research-skills bundle) that the agent relies on to provide prompts/skill logic and can therefore execute or control agent instructions.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata