Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
chinese-calendar
- Confidence
- 93% confidence
- Finding
- chinese-calendar
Security checks across malware telemetry and agentic risk
This is a small local China holiday lookup skill with a minor dependency-pinning caution but no evidence of hidden, destructive, or data-access behavior.
Reasonable to install for local holiday lookups. For repeatable or production use, install chinese-calendar from a trusted source and consider pinning a reviewed version because the current requirement can resolve to future upstream releases.
chinese-calendar
66/66 vendors flagged this skill as clean.