edict-multi-agent-orchestration
Warn
Audited by Snyk on Mar 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs fetching and executing remote code at runtime—e.g., git clone https://github.com/cft0808/edict.git followed by running install.sh, and/or docker run cft0808/sansheng-demo which pulls and runs a remote container image—so these external URLs/images are required runtime dependencies that execute remote code.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata