implementing-infrastructure-as-code-security-scanning
Warn
Audited by Snyk on Jun 20, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill clearly fetches and executes external code at runtime (e.g., GitHub Action references like bridgecrewio/checkov-action@v12 and aquasecurity/tfsec-action@v1.0.3, the Docker image checkmarx/kics:latest, and pip-installed checkov via
pip install checkov), so these are runtime external dependencies that execute remote code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata