dependabot-triage-py
Warn
Audited by Snyk on Aug 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (low risk: 0.10). The workflow reads repo-owned files (lockfiles/manifests/CI configs/CHANGELOG.md from downloaded sdists) after the user provides a Dependabot alert for a specific repository, but it does not ingest arbitrary outsider-authored free text from public feeds/queues without first selecting a specific item.
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.90). The skill clearly runs curl against PyPI at runtime (e.g. "https://pypi.org/pypi//json" and "https://pypi.org/pypi///json") to download package metadata and sdists whose changelog/release text is then parsed and used to drive the safety interlock and prompts, so these external endpoints directly influence agent behavior.
Issues (2)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
Audit Metadata