First Seen
Feb 18, 2026
Last Scanned
Feb 20, 2026
Findings
3
Score
100/100
Findings (3)
Detects pip install of arbitrary packages that modify the host environment
pip install ne Pin all pip packages to exact versions (e.g., pip install package==1.2.3). Use a requirements.txt or pyproject.toml with pinned versions and hash verification.
Likely FP if the match is in documentation showing how to install the skill's own PyPI package.
Detects pip install of arbitrary packages that modify the host environment
pip install ht Pin all pip packages to exact versions (e.g., pip install package==1.2.3). Use a requirements.txt or pyproject.toml with pinned versions and hash verification.
Likely FP if the match is in documentation showing how to install the skill's own PyPI package.
Detects installing packages directly from URLs instead of registries
pip install https://github.com/neuropsychology/NeuroKit/zipball/dev Review installation scripts for commands that persist beyond the package installation (e.g., adding cron jobs, modifying system configs, installing additional packages).
Likely FP if the persistence mechanism is a standard setup step (e.g., adding the tool to PATH) documented in the installation instructions.