memory-notes

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). Flagged because the skill uses memory:// URLs at runtime (e.g., build_context({ url: "memory://api-design-decisions" }) and memory://docs/* in examples) to fetch note content that would be injected into the agent's context and can directly control prompts.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 07:57 PM