kustomize
Warn
Audited by Snyk on Jul 8, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's install instructions fetch and extract a remote kustomize binary at runtime via the GitHub API and release URL (curl https://api.github.com/repos/kubernetes-sigs/kustomize/releases/latest and curl https://github.com/kubernetes-sigs/kustomize/releases/download/...), which downloads and installs remote executable code that the skill relies on.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata