SkillTotal

Is sentence-transformers safe?

No malicious indicators - review capabilities before installing
Notable — review in context (capabilities are not malware):
  • Python dynamic code execution
  • Python filesystem read
  • Python filesystem write/delete

What to do: Nothing here argues against installing it. Grant the capabilities it lists only if you expect the tool to need them.

sentence-transformers is a PyPI package analyzed by SkillTotal's deterministic static scanner. The scan found no malicious indicators. It can: dynamic code execution, filesystem read, filesystem write and network egress — capabilities are what the code can do, not a verdict on intent. Risk score 0/100 (low).

sentence-transformers 6.1.0

python_package · pypi:sentence-transformers
LOW
0
/ 100 risk score
Snapshot · scanned Oct 8, 2026 · sentence-transformers@6.1.0 · engine 0.56.4 / ruleset 62

Automated static-analysis result. It can contain false positives and false negatives, and is not a claim about the intent of sentence-transformers's authors. Report a false positive.

Capabilities — what this component can do (not a risk score):
dynamic code executionfilesystem readfilesystem writenetwork egress

Behavioral traits

How this component maps to the CSA agentic threat model. Descriptive — it never affects the risk score.

Execution authority
Tool Access Control / Direct Tool Access
Filesystem reach
Tool Execution Context
Network egress
Interaction & Communication / Direct Communication

Findings (4)

HIGHPython dynamic code executionST-DYN-PY

The code turns strings into live code at runtime (eval / new Function / exec).

return super().compile(*args, **kwargs)

Why it matters: If those strings aren't fixed and trusted, they become a way to run arbitrary code.

Fix: Avoid evaluating dynamically constructed code; if unavoidable, ensure the input is a trusted constant and never derived from external data.

MEDIUMPython filesystem readST-FS-PY-READ

The component reads files from disk.

with open(ov_config, encoding="utf-8") as f:
with open(config_sentence_transformers_json_path, encoding="utf8") as fIn:
with open(model_card_path, encoding="utf8") as fIn:
with open(modules_json_path, encoding="utf8") as fIn:
with open(config_sentence_transformers_json_path, encoding="utf8") as fIn:
with open(config_path, encoding="utf-8") as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(config_json_path, encoding="utf-8") as fIn:
with open(metadata_path, encoding="utf8") as f:
with open(config_st_json_path, encoding="utf8") as fIn:
with open(config_json_path, encoding="utf-8") as fIn:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a" if output_file_exists else "w", encoding="utf-8") as f:
with open(os.path.join(input_path, "phrasetokenizer_config.json")) as fIn:
with open(os.path.join(input_path, "whitespacetokenizer_config.json")) as fIn:
else open(embeddings_file_path, encoding="utf8") as fIn
for line in open(os.path.join(self.folder, filename), encoding="utf-8"):

Why it matters: Usually legitimate, but worth confirming it can't be steered into reading sensitive files.

Fix: Confirm which files are read and that paths cannot be influenced by untrusted input to reach sensitive locations.

MEDIUMPython filesystem write/deleteST-FS-PY-WRITE

The component writes or deletes files on disk.

shutil.move(save_dir / "openvino_model.xml", save_dir / file_name)
shutil.move(save_dir / "openvino_model.bin", (save_dir / file_name).with_suffix(".bin"))
shutil.copy(bin_source, bin_destination)
with open(os.path.join(path, "config_sentence_transformers.json"), "w", encoding="utf8") as fOut:
shutil.copy(class_file, dest_file)
shutil.copy(needed_file, dest_file)
with open(os.path.join(path, "modules.json"), "w", encoding="utf8") as fOut:
with open(os.path.join(path, "README.md"), "w", encoding="utf8") as fOut:
shutil.copy2(source_path, os.path.join(assets_dir, filename))
with open(config_output_path, "w", encoding="utf-8") as f:
with open(os.path.join(output_path, self.config_file_name), "w", encoding="utf8") as fOut:
shutil.copytree(src, dst, dirs_exist_ok=True)
fOut = open(csv_path, mode="w", encoding="utf-8")
fOut = open(csv_path, mode="a", encoding="utf-8")
with open(csv_path, mode="a", newline="", encoding="utf-8") as f:
with open(csv_path, newline="", mode="w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a", encoding="utf-8") as f:
with open(csv_path, newline="", mode="w", encoding="utf-8") as f:
with open(csv_path, newline="", mode="a", encoding="utf-8") as f:

Why it matters: Usually legitimate, but worth confirming the paths can't be controlled by untrusted input.

Fix: Confirm which files are written/deleted and that paths cannot be influenced by untrusted input.

MEDIUMPython network egressST-NET-PY

The component makes outbound network requests.

with httpx.stream("GET", url, follow_redirects=True) as response:

Why it matters: Usually legitimate, but confirm the destinations are expected and no sensitive data leaves.

Fix: Confirm the destination hosts are expected and that no sensitive data is sent off-host.

Check your own component

Run the same evidence-backed scan on any MCP server, agent skill, or package.

Scan your own component

How we determine this: deterministic static analysis (regex + AST), evidence-anchored, no code execution. Methodology →