localize-ios

Warn

Audited by Snyk on Mar 11, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The included script is invoked at runtime via swift sh .claude/skills/localize-ios/scripts/add_to_xcodeproj.swift, and its header explicitly states dependencies are resolved at runtime by swift-sh (notably the XcodeProj package, e.g. https://github.com/tuist/XcodeProj), meaning the skill will fetch and execute remote package code as a required runtime dependency.

Issues (1)

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 11, 2026, 07:50 PM
Issues
1