v0-dev

Warn

Audited by Snyk on Jul 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The command npx shadcn@latest add "https://v0.dev/chat/b/<project_id>?token=" (SKILL.md:43) is intended to be run at runtime and pulls a generated project from that remote URL directly into your codebase, thereby fetching and injecting remote code/content that can alter execution or prompts.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The SKILL.md explicitly lists "Payments: Stripe" under built-in integrations (SKILL.md:447-450), indicating native support for a payment gateway. Payment gateway integrations (e.g., Stripe) are classified as direct financial execution capabilities, so this skill should be flagged.

Issues (2)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 10, 2026, 09:14 AM
Issues
2
Security Audit — snyk — v0-dev