dependabot-triage

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external security advisories and package changelogs.
  • Ingestion points: The agent fetches Dependabot alert details via the GitHub API (gh api) and scrapes release notes or CHANGELOG.md files from package repositories or registry tarballs.
  • Boundary markers: The instructions do not define explicit boundary markers or delimiters for this external content, nor do they instruct the agent to ignore any potential instructions embedded within those texts.
  • Capability inventory: The skill has significant capabilities, including modifying the filesystem (package.json, lockfiles), executing shell commands (npm, git, gh, pnpm, yarn, bun), and performing network requests.
  • Sanitization: There is no evidence of content sanitization or validation of the external text before it is processed by the LLM.
  • [DYNAMIC_EXECUTION]: The skill uses node -e to execute small JavaScript snippets at runtime to parse JSON data from lockfiles and command outputs.
  • Evidence: SKILL.md contains multiple patterns like node -e "const l=require('./package-lock.json'); ..." and others used to extract version information and dependency trees.
  • [COMMAND_EXECUTION]: The skill relies heavily on executing shell commands to perform its duties, including repository management, package installation, and API interactions.
  • Evidence: Frequent use of gh api, git fetch, git checkout, git rebase, npm install, pnpm install, yarn install, and bun install throughout the SKILL.md instructions. The install.sh script also executes filesystem commands like mkdir and ln.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 04:11 PM
Security Audit — agent-trust-hub — dependabot-triage