core-web-vitals

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (medium risk: 0.30). The skill contains an operational script import and dynamic module import that download executable JavaScript from an untrusted third‑party domain (https://heavy-widget.com/widget.js), which is a direct remote code fetch from a domain that does not match a known trusted vendor and could deliver arbitrary code.

Issues (1)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 26, 2026, 05:19 PM
Issues
1
Security Audit — snyk — core-web-vitals