publish-artifacts

Warn

Audited by Snyk on Jun 17, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). During setup/init the skill runs commands that fetch-and-execute remote code — e.g. "npx wrangler deploy" (which pulls the wrangler package from the npm registry) and installs the Cloudflare agent plugin via "claude plugin install cloudflare@cloudflare" that connects to the Code Mode MCP at https://mcp.cloudflare.com/mcp — these are runtime-fetch-and-execute external dependencies required for the skill to manage Access and deploy the Worker.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 17, 2026, 08:56 AM
Issues
1
Security Audit — snyk — publish-artifacts