ripast
Warn
Audited by Snyk on Jun 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's runtime invocation uses "npx -y @ripast/cli", which fetches and executes remote package code (the package/repository linked at https://github.com/harlan-zw/ripast), so it relies on executing externally fetched code at runtime.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata