Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
requests
- Confidence
- 97% confidence
- Finding
- requests
Security checks across malware telemetry and agentic risk
This is a straightforward Financial Modeling Prep market-calendar skill; its main issue is dependency hygiene, not hidden or malicious behavior.
Install only if you are comfortable using an FMP API key for market-event lookups. Use a dedicated, revocable FMP key, point --file only at simple ticker lists, and prefer a version that pins requests to a maintained safe release.
requests
VirusTotal findings are pending for this skill version.