stelow-product-testing-ai-code
Warn
Audited by Snyk on Jul 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). I flagged runtime installer/CLI invocations that fetch and execute remote code at runtime (the agent-browser npx invocation "npx -y @earendil-works/pi-agent-browser open --url "{URL}" -- snapshot -i" and the git installs "git:github.com/PriNova/pi-agent-codebase-workflows" and "git:github.com/cursor/plugins"), because these commands will download and run external code during skill execution.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata