bruce-doc-converter
Warn
Audited by Snyk on Apr 27, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The README explicitly tells the agent to install/clone the repository at https://github.com/brucevanfdm/bruce-doc-converter at runtime, and the skill then auto-installs pip/npm packages and runs the downloaded conversion scripts (executing remote code that the skill depends on).
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata