create-agent

Warn

Audited by Snyk on Jun 20, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill includes runtime dependencies that will be contacted/pulled during execution — notably the container image pkg.harness.io/vrvdt5ius7uwygso8s0bia/harness-agents/claude-code-plugin:main (pulled and executed at runtime) and external MCP endpoints used by the agent such as https://api.githubcopilot.com/mcp/ and the ngrok example https://harmfully-unregulative-theressa.ngrok-free.dev/mcp (and placeholder https:///mcp) which the agent calls at runtime to perform actions — these endpoints/images therefore execute remote code or directly enable remote control of agent actions.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 20, 2026, 09:50 PM
Issues
1
Security Audit — snyk — create-agent