runway
Warn
Audited by Snyk on Aug 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The README instructs cloning and installing remote code via "git clone --filter=blob:none --sparse https://github.com/zapier/connectors.git" (followed by npm install/run), which fetches and then executes external code at runtime (https://github.com/zapier/connectors.git).
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata