dependabot-triage-py

Pass

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing untrusted external data.
  • Ingestion points: Fetches Dependabot alerts via gh api, release notes via gh release view, and downloads/extracts changelogs from PyPI source distributions (sdist tarballs) in SKILL.md.
  • Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore potentially malicious content within the fetched data.
  • Capability inventory: The skill possesses significant capabilities, including shell command execution (git, gh, python, pip, poetry, uv, etc.), file system modification (manifests and lockfiles), and network access.
  • Sanitization: No escaping, validation, or filtering of the external content is performed before processing.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands to interact with the environment and process data.
  • Python processing: Uses python -c and heredoc scripts (`python
  • <<EOF) in SKILL.mdto dynamically parse TOML files (likepoetry.lock, uv.lock, pdm.lock), compare versions using the packaging` library, and normalize package names. These are implemented as static templates for data processing.
  • System tools: Orchestrates git, gh, ripgrep (rg), and find for repository analysis and triaging tasks.
  • [EXTERNAL_DOWNLOADS]: The skill fetches data and metadata from well-known and trusted external services.
  • GitHub: Retrieves vulnerability alerts and release notes using the gh CLI (api.github.com).
  • PyPI: Fetches package metadata and source distributions from pypi.org using curl to determine patched versions and extract changelogs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 2, 2026, 12:20 PM
Security Audit — agent-trust-hub — dependabot-triage-py