Dynamic code execution detected.
Critical
- Code
- suspicious.dynamic_code_execution
- Location
- venv/lib/python3.14/site-packages/pip/_vendor/pygments/formatters/__init__.py:91
Security audit
Security checks across malware telemetry and agentic risk
This skill does what it claims: it sends a tracking number and optional postal code to Track123 to return parcel tracking status.
Install only if you are comfortable providing a Track123 API secret and sending tracking numbers, and optionally postal codes, to Track123. The bundled virtual environment is unnecessary but did not show harmful behavior in this review.
66/66 vendors flagged this skill as clean.
Detected: suspicious.dynamic_code_execution, suspicious.exposed_secret_literal, suspicious.insecure_tls_verification