dependabot-triage-py
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by ingesting and processing untrusted external data.
- Ingestion points: Fetches Dependabot alerts via
gh api, release notes viagh release view, and downloads/extracts changelogs from PyPI source distributions (sdisttarballs) inSKILL.md. - Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore potentially malicious content within the fetched data.
- Capability inventory: The skill possesses significant capabilities, including shell command execution (
git,gh,python,pip,poetry,uv, etc.), file system modification (manifests and lockfiles), and network access. - Sanitization: No escaping, validation, or filtering of the external content is performed before processing.
- [COMMAND_EXECUTION]: The skill frequently executes shell commands to interact with the environment and process data.
- Python processing: Uses
python -cand heredoc scripts (`python - <<EOF
) inSKILL.mdto dynamically parse TOML files (likepoetry.lock,uv.lock,pdm.lock), compare versions using thepackaging` library, and normalize package names. These are implemented as static templates for data processing. - System tools: Orchestrates
git,gh,ripgrep(rg), andfindfor repository analysis and triaging tasks. - [EXTERNAL_DOWNLOADS]: The skill fetches data and metadata from well-known and trusted external services.
- GitHub: Retrieves vulnerability alerts and release notes using the
ghCLI (api.github.com). - PyPI: Fetches package metadata and source distributions from
pypi.orgusingcurlto determine patched versions and extract changelogs.
Audit Metadata