angular-developer

Warn

Audited by Snyk on May 12, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill documents an MCP server that the agent may invoke at runtime (via running "npx @angular/cli mcp", which fetches and executes remote npm code) and explicitly exposes a tool that searches/fetches documentation from https://angular.dev, meaning https://angular.dev (and the npx @angular/cli mcp invocation) are runtime external dependencies that can be used to inject remote content into the agent's context.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 12, 2026, 01:54 AM
Issues
1