velt-setup-best-practices
Warn
Audited by Snyk on Feb 15, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill includes a runtime-loaded CDN script (e.g. https://cdn.velt.dev/lib/sdk@latest/velt.js and the versioned https://cdn.velt.dev/lib/sdk@4.6.10/velt.js) which is fetched and executed in client pages and is a required dependency for non-React setups, so it executes remote code at runtime.
Audit Metadata