Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
fiona>=1.8.0 numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0
- Confidence
- 95% confidence
- Finding
- fiona>=1.8.0
Security audit
Security checks across malware telemetry and agentic risk
This skill appears to be a local satellite-image processing tool with ordinary geospatial dependencies and no evidence of hidden network, credential, persistence, or destructive behavior.
Install it in a controlled Python environment and consider pinning the dependencies before production use. Run it only on imagery and output directories you choose, and verify documentation examples against `--help` because a few advanced flags appear to be documented but not implemented.
fiona>=1.8.0 numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0
fiona>=1.8.0 numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0 shapely>=1.8.0
fiona>=1.8.0 numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0 shapely>=1.8.0 tqdm>=4.64.0
fiona>=1.8.0 numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0 shapely>=1.8.0 tqdm>=4.64.0
numpy>=1.21.0 rasterio>=1.3.0 scipy>=1.7.0 shapely>=1.8.0 tqdm>=4.64.0
rasterio>=1.3.0 scipy>=1.7.0 shapely>=1.8.0 tqdm>=4.64.0
65/65 vendors flagged this skill as clean.
Detected: suspicious.dynamic_code_execution