time-tracking
Warn
Audited by Snyk on May 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The script uses bundler.inline with source "https://rubygems.org", which will fetch and install gems (remote code) at runtime that the CLI requires to execute, so remote code from https://rubygems.org is fetched and executed during skill runtime.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata