Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
dataclasses docx pdfplumber pypdf2
- Confidence
- 95% confidence
- Finding
- dataclasses
Security checks across malware telemetry and agentic risk
This document-processing skill appears purpose-aligned, but its unpinned and vulnerable document parser dependencies make it risky to install for untrusted PDFs or DOCX files.
Install only if you trust the documents being processed or can run the skill in a constrained environment. Prefer a version that pins dependencies, updates or replaces vulnerable PDF/DOCX parsers, and documents input size, timeout, and sandboxing limits.
dataclasses docx pdfplumber pypdf2
dataclasses docx pdfplumber pypdf2 python-docx
dataclasses docx pdfplumber pypdf2 python-docx
dataclasses docx pdfplumber pypdf2 python-docx
docx pdfplumber pypdf2 python-docx
66/66 vendors flagged this skill as clean.