feishu-max-saver
Warn
Audited by Snyk on May 5, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The setup instructions instruct cloning and building remote code via "git clone https://github.com/d-wwei/feishu-max-saver-skill.git" followed by npm install && npm run build, which fetches and executes external code required to install/run the skill, so this repository URL is a runtime/execution-time external dependency that could control agent behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata