kotlin-multiplatform-shadcn-compose
Warn
Audited by Snyk on Aug 1, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The bundled script fetch_component_signature.py issues live requests to GitHub (e.g. "https://api.github.com/repos/{REPO}/git/trees/main?recursive=1" and "https://raw.githubusercontent.com/{REPO}/main/{path}") at runtime to pull component source/signatures that are then injected into the agent's verification/output flow, so the skill depends on and uses remote content to control its prompts/outputs.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata