ego-browser
Fail
Audited by Snyk on Jul 25, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E005: Suspicious download URL detected in skill instructions.
- Suspicious download URL detected (high risk: 0.80). Two cdn.ego.app links are direct .dmg installer downloads (macOS executables) hosted on a CDN, which are higher-risk download sources unless vendor authenticity and integrity (signatures/checksums) are verified; the remaining URLs are benign navigation/search endpoints.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The install script downloads and mounts a remote installer DMG (executes its contents), fetching from https://cdn.ego.app/channel/egobrowser_npx_referral/setup/macos/arm64/egolite.dmg and https://cdn.ego.app/channel/egobrowser_npx_referral/setup/macos/x64/egolite.dmg which are runtime-fetched executables required to install the ego lite dependency.
Issues (2)
E005
CRITICALSuspicious download URL detected in skill instructions.
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata