zeroize-audit

Fail

Audited by Snyk on Jul 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (high risk: 0.80). The GitHub repo https://github.com/oraios/serena is an unvetted third‑party source explicitly referenced as something fetched/run (uvx --from git+...), which can be used to distribute code/executables and therefore poses a higher risk; the other two URLs point to official documentation/specs and are low risk.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill specifies fetching and running Serena at runtime via "uvx --from git+https://github.com/oraios/serena" (references/mcp-analysis.md), which fetches and executes remote code that the pipeline relies on for MCP semantic analysis.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 15, 2026, 12:59 PM
Issues
2
Security Audit — snyk — zeroize-audit