beaver-release-skills

Warn

Audited by Snyk on May 3, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill explicitly requires and invokes the Changesets CLI (referenced at https://github.com/changesets/changesets and run via commands like npx changeset version/npx changeset publish), which will fetch and execute external package code at runtime and is a required dependency.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 3, 2026, 01:00 PM
Issues
1