T08 · Insecure Dependencies
- Location
scripts/download_international_qs.py:62- Finding
Unverified and Unbounded Downloads from Third-Party and Typo-Like Sources
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a construction cost-estimation toolkit with some overstated accuracy claims and an unsafe optional document downloader, but no evidence of hidden control, credential theft, persistence, or destructive behavior.
Install only if you are comfortable treating this as an advisory construction-estimation aid, not a guaranteed +/-3% professional costing system. Avoid running the international PDF downloader unless you verify the source URLs and scan downloaded documents first.
scripts/download_international_qs.py:62Unverified and Unbounded Downloads from Third-Party and Typo-Like Sources
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
The analysis consistently indicates weaker accuracy bands, absent advanced AI implementations, and version inconsistency relative to the manifest's strong claims. In a skill ecosystem, this is a high-risk transparency failure because it can alter review outcomes, user consent, and authorization decisions.
No suspicious patterns detected.