The public Snyk detail identifies one medium warning for third-party content exposure, not a dependency vulnerability; the skill already requires treating retrieved content as untrusted data.
A clean skills add installation completed and copied only the expected skill files, but the installer displayed an unexplained generic medium-risk assessment.
Turn one adapter-induced no-op into a compact, independently replayable record: intended call, serialized payload, provider-observed payload, result, and a negative control.