graph-query
Warn
Audited by Snyk on Feb 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill's prerequisite instructs fetching and running remote install code via "git clone https://github.com/23blocks-OS/ai-maestro-plugins.git" followed by executing ./install-graph-tools.sh, which downloads remote code and executes it as a required dependency, so it presents a runtime risk.
Audit Metadata