Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
"author": "OpenClaw", "license": "MIT", "dependencies": { "pandas": "^2.0.0", "requests": "^2.31.0", "beautifulsoup4": "^4.12.0" }- Confidence
- 85% confidence
- Finding
- "pandas": "^2.0.0"
Security checks across malware telemetry and agentic risk
The skill code appears to fetch public A-share market data, but its install metadata includes mismatched and unpinned dependencies that should be reviewed before installation.
Review or remove the package.json dependency declarations before installing, and install in an isolated Python environment with pinned, vetted versions. The runtime behavior appears limited to public finance data requests, but the dependency metadata needs maintainer attention.
"author": "OpenClaw",
"license": "MIT",
"dependencies": {
"pandas": "^2.0.0",
"requests": "^2.31.0",
"beautifulsoup4": "^4.12.0"
}"license": "MIT",
"dependencies": {
"pandas": "^2.0.0",
"requests": "^2.31.0",
"beautifulsoup4": "^4.12.0"
}
}"dependencies": {
"pandas": "^2.0.0",
"requests": "^2.31.0",
"beautifulsoup4": "^4.12.0"
}
}pandas requests beautifulsoup4
pandas requests beautifulsoup4
pandas requests beautifulsoup4
64/64 vendors flagged this skill as clean.