graph-query

Warn

Audited by Snyk on Feb 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill's prerequisite instructs fetching and running remote install code via "git clone https://github.com/23blocks-OS/ai-maestro-plugins.git" followed by executing ./install-graph-tools.sh, which downloads remote code and executes it as a required dependency, so it presents a runtime risk.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 23, 2026, 01:28 AM