create-agent-with-sanity-context
Warn
Audited by Snyk on Feb 24, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill creates an MCP client at runtime using the SANITY_CONTEXT_MCP_URL (https://api.sanity.io/:apiVersion/agent-context/:projectId/:dataset/:slug) and also fetches an agent.config systemPrompt from Sanity, meaning remote Sanity/MCP content is fetched at runtime and directly controls the agent's system prompt/tools (a required dependency).
Audit Metadata