external-agents
Warn
Audited by Snyk on Jul 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs hosts to connect to runtime MCP endpoints (e.g., https://dispatch.agent-native.com/_agent-native/mcp and https://mail.agent-native.com/_agent-native/mcp), and the docs state hosts (notably Claude) fetch signed app HTML from those endpoints and hydrate/execute it inside the host iframe at runtime, which meets the criteria for fetching remote content that executes in the host.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata