computer-use
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly performs runtime installation/invocation of external skills (via "npx skills add ") and names packages that would be fetched and executed at runtime — stablyai/orca@computer-use, web-infra-dev/midscene-skills@computer-automation, and am-will/codex-skills@gemini-computer-use — which means remote code would control agent behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata