catchup

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The skill executes git network commands (git fetch origin master) that fetch content from the repository remote "origin" (the configured git remote URL), and that fetched code/diff output is then read and injected into the agent's analysis context at runtime, so remote content can directly drive the agent's outputs.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 12:33 AM