brainstorming
Warn
Audited by Snyk on May 9, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly runs GitHub API calls at runtime (e.g.,
gh api repos/primatrix/wiki/contents/docs/rfc/NNNN-<topic>.md -H "Accept: application/vnd.github.raw" -f ref="rfc/NNNN-<topic>") to fetch RFC content and inject it into the spec-document-reviewer prompt, meaning remote content is fetched during runtime and used directly to drive agent instructions.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata