light-tool-selection
Warn
Audited by Snyk on Jun 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). Yes — the SKILL explicitly instructs runtime discovery/installation and use of external MCP servers and skills (e.g., querying the registry at https://registry.modelcontextprotocol.io and installing/starting packages via the skills ecosystem/skills.sh + npx), which will fetch and run remote code and/or return resources (via resources/read / tools/call) that get injected into the agent context and thus can directly control prompts or execute code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata