remix-agent-publish

Warn

Audited by Snyk on Mar 6, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 1.00). The skill explicitly instructs the agent to fetch the OpenAPI spec at runtime from https://api.remix.gg/docs/json and rely on that spec as the source of truth for methods/paths/params, so the remotely fetched content is a required runtime dependency that directly controls the agent's generated instructions for API calls.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 6, 2026, 12:42 PM