animade

Fail

Audited by Snyk on Sep 13, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E005: Suspicious download URL detected in skill instructions.

  • Suspicious download URL detected (medium risk: 0.30). The bootstrap script installs the animade-cli npm package from an arbitrary cloud origin domain (animade.codyx.lol) rather than official npm registry channels.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The bootstrap script fetches configuration metadata and an installation package specification from https://animade.codyx.lol, an arbitrary/uncontrolled third-party domain, which constitutes an unverified external runtime dependency under weak/unknown provenance.

Issues (2)

E005
CRITICAL

Suspicious download URL detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 13, 2026, 02:45 PM
Issues
2
Security Audit — snyk — animade