neo4j-cypher-skill
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs the agent at runtime to fetch and parse Neo4j docs and changelogs (e.g. https://neo4j.com/developer/kb/neo4j-supported-versions/, https://neo4j.com/docs/cypher-manual/4.4/deprecations-additions-removals-compatibility/, https://neo4j.com/docs/cypher-manual/5/deprecations-additions-removals-compatibility/, https://neo4j.com/docs/cypher-manual/25/deprecations-additions-removals-compatibility/) and use that fetched content to determine versions and drive the upgrade plan, so these runtime-fetched URLs directly control agent instructions.
Audit Metadata