Security Audit
dkyazzentwatwa/chatgpt-skills:date-normalizer
github.com/dkyazzentwatwa/chatgpt-skillsTrust Assessment
dkyazzentwatwa/chatgpt-skills:date-normalizer received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 3 findings: 0 critical, 0 high, 2 medium, and 0 low severity. Key findings include Unpinned Python dependency version, Broadly Pinned Dependencies.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 24, 2026 (commit d4bad335). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings3
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Unpinned Python dependency version Requirement 'python-dateutil>=2.8.0' is not pinned to an exact version. Pin Python dependencies with '==<exact version>'. | Dependencies | date-normalizer/scripts/requirements.txt:1 | |
| MEDIUM | Unpinned Python dependency version Requirement 'pandas>=2.0.0' is not pinned to an exact version. Pin Python dependencies with '==<exact version>'. | Dependencies | date-normalizer/scripts/requirements.txt:2 | |
| INFO | Broadly Pinned Dependencies The `requirements.txt` file uses broad version specifiers (`>=`) for `python-dateutil` and `pandas`. While common, this practice can lead to non-reproducible builds and may introduce unexpected vulnerabilities or breaking changes if a new major/minor version is released with issues. For enhanced security and stability, it is recommended to pin dependencies to exact versions (`==`) or use a lock file mechanism. Pin dependencies to exact versions (e.g., `python-dateutil==2.8.2`, `pandas==2.1.4`) after verifying compatibility, or use a lock file mechanism like `pip-tools` to generate a `requirements.lock` file. | LLM | scripts/requirements.txt:1 |
Scan History
Embed Code
[](https://skillshield.io/report/5a22f0ef8703426d)
Powered by SkillShield