Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
tree-sitter>=0.23.0 tree-sitter-c>=0.23.0 pycparser>=2.22
- Confidence
- 89% confidence
- Finding
- tree-sitter>=0.23.0
Security checks across malware telemetry and agentic risk
This skill appears to be a coherent C-language helper library, with only low-level dependency reproducibility risk noted.
Reasonable to install for C project analysis. For stricter environments, install it in a sandbox and use a lockfile or pinned dependency versions before running automated workflows.
tree-sitter>=0.23.0 tree-sitter-c>=0.23.0 pycparser>=2.22
tree-sitter>=0.23.0 tree-sitter-c>=0.23.0 pycparser>=2.22
tree-sitter>=0.23.0 tree-sitter-c>=0.23.0 pycparser>=2.22
53/53 vendors flagged this skill as clean.