dependabot-triage-py

Warn

Audited by Snyk on Aug 2, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (low risk: 0.10). The workflow reads repo-owned files (lockfiles/manifests/CI configs/CHANGELOG.md from downloaded sdists) after the user provides a Dependabot alert for a specific repository, but it does not ingest arbitrary outsider-authored free text from public feeds/queues without first selecting a specific item.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill clearly runs curl against PyPI at runtime (e.g. "https://pypi.org/pypi//json" and "https://pypi.org/pypi///json") to download package metadata and sdists whose changelog/release text is then parsed and used to drive the safety interlock and prompts, so these external endpoints directly influence agent behavior.

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 12:20 PM
Issues
2
Security Audit — snyk — dependabot-triage-py