dividend-tracking

Warn

Audited by Snyk on Feb 15, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill opens the Google Sheets URL at https://docs.google.com/spreadsheets/d/{spreadsheet_id}/edit#gid=2068577140 at runtime via browser automation to click an "Add Dividend" button which triggers the sheet's Apps Script (remote code) that the workflow depends on, so this external URL leads to execution of remote code required by the skill.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 15, 2026, 10:17 PM