load-testing
Warn
Audited by Snyk on Aug 10, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill includes CI/setup commands that fetch and install remote binaries (the k6 apt repo and GPG key and a JMeter tarball), e.g. https://dl.k6.io/deb and hkp://keyserver.ubuntu.com:80 and https://archive.apache.org/dist/jmeter/binaries/apache-jmeter-5.6.3.tgz, which are runtime external dependencies that download and execute code when the workflow or setup is run.
MEDIUM W013: Attempt to modify system services in skill instructions.
- Attempt to modify system services in skill instructions detected (high risk: 1.00). The skill includes a CI step that runs sudo to add apt keyrings and write to /etc/apt/sources.list.d and then apt-get installs packages (lines 345-355), i.e. explicit instructions to modify system files with elevated privileges on the host.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W013
MEDIUMAttempt to modify system services in skill instructions.
Audit Metadata