compute-env-setup
Warn
Audited by Snyk on Jul 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill runs remote install/fetch steps during env build that download and execute third‑party code as required dependencies (e.g., pip installing from git+https://github.com/bowang-lab/scGPT.git and using find_links=https://data.pyg.org/whl/torch-2.7.0+cu126.html to fetch wheels), so these URLs are runtime external dependencies that can execute code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata