STDF Reader
Security checks across static analysis, malware telemetry, and agentic risk
Overview
The skill is an instruction-only wrapper that tells the agent to install and run a PyPI CLI (stdf-reader) to parse STDF files; its requirements and instructions are consistent with the stated purpose, but the actual PyPI package is external and was not provided for inspection.
This skill's instructions are coherent with its purpose, but it relies on installing the external PyPI package `stdf-reader` which was not bundled for review. Before installing or running: (1) verify the package on PyPI (author, download counts, recent releases) and inspect its source repository if available; (2) install and run it in an isolated virtualenv or disposable environment; (3) avoid giving it files that contain secrets or PII until you trust the package; (4) consider reviewing the package code for network activity or unexpected file access; and (5) if you need stronger assurance, request the skill owner to include the package source or a vetted install spec.
Static analysis
No static analysis findings were reported for this release.
VirusTotal
VirusTotal findings are pending for this skill version.
Risk analysis
No visible risk-analysis findings were reported for this release.
