NYC

iblipper

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill's runtime renderer navigates to and interacts with the remote web app at https://andyed.github.io/iblipper2025/ (via Playwright's page.goto and page.evaluate calling window.useRSVPStore), so untrusted remote JavaScript is fetched and executed at runtime and the skill depends on that site to produce GIFs/behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 01:00 PM