learnings

Warn

Audited by Snyk on Feb 28, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.70). The helper script will run "brew install tkersey/tap/learnings" at runtime on macOS, which fetches and installs remote code (the tkersey/tap Homebrew formula providing the learnings/append_learning binaries) that the skill then executes and relies on, so this is a runtime external dependency that executes remote code.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 28, 2026, 11:45 AM