Seems reasonable enough, but why would it (allegedly) send environment variables back via a POST? Even if it's entirely in good faith, I'd rather some random package not have my `env` output..
https://snyk.io/blog/snyk-security-labs-testing-update-curso...