What the reviewer found
Sanity CMS documentation: the '?instructions=' and '?groqFilter=' query params are Sanity's own product feature letting Studio users reconfigure their content agent, not an instruction telling the installing agent to override its own guidelines. The curl example authenticates to api.sanity.io with a bearer token, which is the tool's own vendor API — flagged low for that outbound call; Socket/agent-trust-hub both passed it and Snyk's warning is unspecified but not corroborated by anything in the body.
What was read
The file as it ships in sanity-io/context:
skills/create-agent-with-sanity-context/SKILL.md
What the static scan said
The scan flagged 3things. The reviewer kept 0 and dismissed 3 as false.
P1Instruction-override phrasing — false positiveAR3Nullifies safety policies — false positiveNETMakes network calls — false positive
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.