hzdb-cli
Warn
Audited by Snyk on May 4, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.70). The skill exposes a runtime docs-fetch tool (e.g., hzdb docs fetch https://developers.meta.com/horizon/documentation/unity/unity-scene-overview) which pulls external documentation at runtime and can be injected into an agent's context to directly influence prompts/instructions, so it is an external runtime dependency that can control agent behavior.
Issues (1)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata