create-workflow
Warn
Audited by Snyk on Feb 23, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill references and (auto-)configures an MCP documentation server at https://docs.vapi.ai/_mcp/server which the agent’s searchDocs/MCP integration can call at runtime to fetch documentation that may be injected into the model context and thus directly influence prompts/behavior.
Audit Metadata