sast-configuration
Warn
Audited by Snyk on Jul 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The GitHub Action reference "returntocorp/semgrep-action@v1" (SKILL.md:78) and the pre-commit repo "https://github.com/returntocorp/semgrep" (SKILL.md:88) are fetched and executed at runtime by CI/pre-commit and thus load and run remote code from those external repositories.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata