post-audit
Fail
Audited by Snyk on Jun 17, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). The GitHub repo (casoon/astro-post-audit) is potentially risky because it pulls a prebuilt Rust binary automatically during npm install from a third‑party GitHub/npm package (a common vector for distributing executables), whereas example.com is just a benign placeholder and not a download source.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The integration explicitly downloads and runs a remote Rust binary during npm install / when invoking the CLI (e.g., via "npx @casoon/astro-post-audit" and the repository https://github.com/casoon/astro-post-audit), so external content is fetched at runtime and executed.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata