pulumi-esc
Warn
Audited by Snyk on Feb 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill explicitly instructs using the web-fetch tool at runtime to retrieve Pulumi docs (e.g., https://www.pulumi.com/docs/esc/integrations/dynamic-login-credentials/aws-login/), and that fetched content is incorporated into agent guidance, so external content can directly control prompts/instructions.
Audit Metadata