text-code-edit

Warn

Audited by Snyk on Jun 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill accepts and at runtime fetches an external source_code_url (placeholder "{code_url}") via the meitu CLI (--source_code_url "{code_url}"), injecting that fetched source into the model/context to drive edits, so arbitrary remote content can directly control agent behavior.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 15, 2026, 06:03 AM
Issues
1
Security Audit — snyk — text-code-edit