remix-agent-publish
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill explicitly instructs the agent to fetch the OpenAPI spec at runtime from https://api.remix.gg/docs/json and rely on that spec as the source of truth for methods/paths/params, so the remotely fetched content is a required runtime dependency that directly controls the agent's generated instructions for API calls.
Audit Metadata