claude-docs-consultant
Warn
Audited by Snyk on Feb 17, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). This skill explicitly performs WebFetch at runtime to retrieve and inject external documentation (e.g., https://code.claude.com/docs/en/[doc-name].md and specifically https://code.claude.com/docs/en/claude_code_docs_map.md), and that fetched content is used to control the agent's instructions and behavior, making it a runtime dependency that directly influences prompts.
Audit Metadata