Is sentence-transformers safe?
- Python dynamic code execution
- Python filesystem read
- Python filesystem write/delete
What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.
sentence-transformers is a PyPI package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators. It can: dynamic code execution, filesystem read, filesystem write and network egress — capabilities are what the code can do, not a verdict on intent. Risk score 0/100 (low).
sentence-transformers 6.1.0
Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of sentence-transformers's authors. Report a false positive.
Behavioral traits
How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.
Findings (4)
The code turns strings into live code at runtime (eval / new Function / exec).
return super().compile(*args, **kwargs)
Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.
Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.
The component reads files from disk.
with open(ov_config, encoding="utf-8") as f:
with open(config_sentence_transformers_json_path, encoding="utf8") as fIn:
with open(model_card_path, encoding="utf8") as fIn:
with open(modules_json_path, encoding="utf8") as fIn:
with open(config_sentence_transformers_json_path, encoding="utf8") as fIn:
with open(config_path, encoding="utf-8") as f:
with open(index_path) as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(config_json_path, encoding="utf-8") as fIn:
with open(metadata_path, encoding="utf8") as f:
with open(config_st_json_path, encoding="utf8") as fIn:
with open(config_json_path, encoding="utf-8") as fIn:
else open(filepath, encoding="utf8") as fIn
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(json_path, mode=mode, encoding="utf-8") as fOut:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(os.path.join(input_path, "phrasetokenizer_config.json")) as fIn:
with open(os.path.join(input_path, "whitespacetokenizer_config.json")) as fIn:
else open(embeddings_file_path, encoding="utf8") as fIn
for line in open(os.path.join(self.folder, filename), encoding="utf-8"):
Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.
Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.
The component writes or deletes files on disk.
shutil.move(save_dir / "openvino_model.xml", save_dir / file_name)
shutil.move(save_dir / "openvino_model.bin", (save_dir / file_name).with_suffix(".bin"))shutil.move(source, destination)
shutil.copy(source, destination)
shutil.copy(bin_source, bin_destination)
with open(os.path.join(path, "config_sentence_transformers.json"), "w", encoding="utf8") as fOut:
shutil.copy(class_file, dest_file)
shutil.copy(needed_file, dest_file)
with open(os.path.join(path, "modules.json"), "w", encoding="utf8") as fOut:
with open(os.path.join(path, "README.md"), "w", encoding="utf8") as fOut:
shutil.copy2(source_path, os.path.join(assets_dir, filename))
with open(config_output_path, "w", encoding="utf-8") as f:
with open(os.path.join(output_path, self.config_file_name), "w", encoding="utf8") as fOut:
shutil.copytree(src, dst, dirs_exist_ok=True)
shutil.copy(src, dst)
fOut = open(csv_path, mode="w", encoding="utf-8")
fOut = open(csv_path, mode="a", encoding="utf-8")
with open(csv_path, mode="a", newline="", encoding="utf-8") as f:
with open(csv_path, newline="", mode="w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a", encoding="utf-8") as f:
fOut = open(csv_path, mode="w", encoding="utf-8")
fOut = open(csv_path, mode="a", encoding="utf-8")
with open(csv_path, newline="", mode="w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a", encoding="utf-8") as f:
fOut = open(csv_path, mode="w", encoding="utf-8")
Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.
Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.
The component makes outbound network requests.
import httpx
with httpx.stream("GET", url, follow_redirects=True) as response:Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.
Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.
Check your own component
Run the same evidence-backed scan on any MCP server, agent skill, or package.
Scan your own componentHow we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →