mf-integrate
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill config includes a demo remote that points to https://unpkg.com/module-federation-rslib-provider@latest/dist/mf/mf-manifest.json which is fetched at app runtime to load remote modules (i.e., executable JS), meaning remote content can execute code and directly controls what is loaded into the app.
Audit Metadata