SkillSpector · slo-sli-sla
independent scanner by NVIDIA · skill by chimeranext · how it works ↗
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.; Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.; Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.; +1 more
scanned 2026-08-22
Findings (8)
Credentials or environment variables flow to a network sink. This is a high-confidence indicator of credential exfiltration.
scripts/slo_api.py
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
scripts/requirements.txt
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
scripts/requirements.txt
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
scripts/requirements.txt
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
scripts/requirements.txt
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
scripts/requirements.txt
Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.
scripts/requirements.txt
Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.
scripts/requirements.txt
What the verdicts mean
SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.
Overall severity LOW (risk score in the safe range)
Overall severity MEDIUM
Overall severity HIGH
Overall severity CRITICAL
Scan could not complete