ui-craftsman
Warn
Audited by Snyk on Feb 21, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill instructs loading and executing third‑party scripts at runtime — e.g. https://unpkg.com/react@18/umd/react.production.min.js, https://unpkg.com/react-dom@18/umd/react-dom.production.min.js, https://unpkg.com/@babel/standalone/babel.min.js, https://cdn.tailwindcss.com, and https://unpkg.com/framer-motion@11/dist/framer-motion.js (and runtime image URLs like https://images.unsplash.com/...), which are required runtime dependencies that execute remote code and therefore present a supply-chain/execution risk.
Audit Metadata