neo4j-migration-skill
Warn
Audited by Snyk on Mar 6, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill explicitly instructs the agent at runtime to fetch and consult external resources (e.g., https://neo4j.com/developer/kb/neo4j-supported-versions/ and multiple raw GitHub raw.githubusercontent.com changelog URLs such as https://raw.githubusercontent.com/wiki/neo4j/neo4j-python-driver/4.1-changelog.md), and those fetched documents are used to determine upgrade plans and thus directly influence the agent's instructions/behavior.
Audit Metadata