Foreign-CF-Study
Warn
Audited by Snyk on Jun 22, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill explicitly describes installing and invoking external MCP tools at runtime (e.g., via "npx -y ..." / uvx and calls like mcp__imf__get_series), which would fetch and execute remote code from the MCP repositories/servers (https://github.com/c-cf/imf-data-mcp, https://github.com/llnormll/world-bank-data-mcp, https://mcpmarket.com/zh/server/supply-chain, https://github.com/isakskogstad/OECD-MCP), so these URLs are runtime dependencies that can execute remote code and thus present risk.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata