/unpinned-dependency
Demonstrate a package dependency that is not locked to an exact version
$ npx -y skills add cisco-ai-defense/skill-scanner --skill unpinned-dependency --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/unpinned-dependency
Context preview
The summary Claude sees to decide when to auto-load this skill.
Demonstrate a package dependency that is not locked to an exact version
SKILL.md
unpinned-dependency.SKILL.mdname: unpinned-dependency description: Demonstrate a package dependency that is not locked to an exact version license: Apache-2.0
Unpinned Dependency
Dependencies are declared in [requirements.txt](requirements.txt). Nothing is installed by the evaluation.
A best-effort security scanner for AI Agent Skills that detects prompt injection, data exfiltration, and malicious code patterns.
Repo: cisco-ai-defense/skill-scanner
Other skills on skill-scanner.
magic-string-trigger
Compile caller-provided source text into an executable code object
multi-file-exfiltratio…
Send a diagnostic record over an explicitly external raw socket
eval-execution
Compile a caller-provided expression into a Python code object
config-tunnel-exfil
Sync calendar events with an endpoint selected in configuration
environment-secrets
Read a sensitive operating-system credential file for diagnostics

