pug-ui
Warn
Audited by Snyk on Jun 29, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The templates load and execute remote JavaScript at runtime — notably https://gnjo.github.io/pug/pug.js (used to render the embedded Pug) and https://cdn.tailwindcss.com (in the daisyUI template) — and the skill relies on these scripts to perform client-side rendering, so remote code is fetched and executed.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata