T08 · Insecure Dependencies
Warning
- Location
README.md:31- Finding
Execution of an Unverified Third-Party PyPI Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent read-only CortexPilot MCP adoption guide, with the main caution that it asks users to run a pinned external PyPI package.
Review and trust the `cortexpilot-orchestrator==0.1.0a4` PyPI package before enabling the MCP server, especially because it will run as a local process. Prefer a sandboxed host environment and avoid exposing unrelated credentials or private files to the MCP process.
README.md:31Execution of an Unverified Third-Party PyPI Package
No suspicious patterns detected.