Unpinned Dependencies
Low
- Category
- Supply Chain
- Content
rich PyYAML
- Confidence
- 96% confidence
- Finding
- The dependency `rich` is unpinned, so future installs may resolve to different versions with changed behavior or newly introduced vulnerabilities. While this is a supply-chain hygiene issue rather than an immediate exploit by itself, it reduces build reproducibility and can expose the skill to unexpected security regressions.
