pi-extension-development
Warn
Audited by Snyk on Aug 25, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill contains explicit runtime install commands that fetch and load remote Git repositories (e.g., git:github.com/OWNER/REPO and git:github.com/OWNER/REPO@v), which will retrieve and execute extension code when installed and thus directly control agent behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata