Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
cv2 dataclasses imagehash matplotlib
- Confidence
- 95% confidence
- Finding
- cv2
Security checks across malware telemetry and agentic risk
This is a local image/PDF analysis tool with dependency hygiene and reliability issues, but no evidence of hidden access, data exfiltration, credential use, or destructive behavior.
Install only in an isolated virtual environment, replace requirements.txt with pinned canonical packages such as opencv-python and Pillow, and test folder and tampering modes before relying on results. Use dedicated output and temp directories, and delete generated reports or extracted page images if the manuscript is confidential.
cv2 dataclasses imagehash matplotlib
cv2 dataclasses imagehash matplotlib numpy pdf2image
cv2 dataclasses imagehash matplotlib numpy pdf2image pil
dataclasses imagehash matplotlib numpy pdf2image pil
imagehash matplotlib numpy pdf2image pil
matplotlib numpy pdf2image pil
67/67 vendors flagged this skill as clean.