robel-auth
Warn
Audited by Snyk on Jul 30, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill's runtime script (invoked by the preferred command) uses curl to download upstream markdown that the skill treats as the source-of-truth and thus directly influences agent instructions by fetching: "https://raw.githubusercontent.com/robelest/convex-auth/main/README.md", "https://raw.githubusercontent.com/robelest/convex-auth/release/README.md", and "https://raw.githubusercontent.com/get-convex/self-hosting/main/INTEGRATION.md".
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata