create-workflow

Warn

Audited by Snyk on Feb 23, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.80). The skill references and (auto-)configures an MCP documentation server at https://docs.vapi.ai/_mcp/server which the agent’s searchDocs/MCP integration can call at runtime to fetch documentation that may be injected into the model context and thus directly influence prompts/behavior.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 23, 2026, 07:00 PM