kucoin-openapi-skill
Warn
Audited by Snyk on Mar 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill requires fetching the curated OpenAPI schema at https://raw.githubusercontent.com/holon-run/uxc/main/skills/kucoin-openapi-skill/references/kucoin-public.openapi.json during setup/runtime (used in the
uxc link --schema-urlflow), and that JSON schema directly controls the CLI's available operations/help (i.e., the agent's runtime instruction surface) and is a required dependency.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata