dependabot-triage
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because it ingests and processes untrusted data from external security advisories and package changelogs.
- Ingestion points: The agent fetches Dependabot alert details via the GitHub API (
gh api) and scrapes release notes orCHANGELOG.mdfiles from package repositories or registry tarballs. - Boundary markers: The instructions do not define explicit boundary markers or delimiters for this external content, nor do they instruct the agent to ignore any potential instructions embedded within those texts.
- Capability inventory: The skill has significant capabilities, including modifying the filesystem (
package.json, lockfiles), executing shell commands (npm,git,gh,pnpm,yarn,bun), and performing network requests. - Sanitization: There is no evidence of content sanitization or validation of the external text before it is processed by the LLM.
- [DYNAMIC_EXECUTION]: The skill uses
node -eto execute small JavaScript snippets at runtime to parse JSON data from lockfiles and command outputs. - Evidence:
SKILL.mdcontains multiple patterns likenode -e "const l=require('./package-lock.json'); ..."and others used to extract version information and dependency trees. - [COMMAND_EXECUTION]: The skill relies heavily on executing shell commands to perform its duties, including repository management, package installation, and API interactions.
- Evidence: Frequent use of
gh api,git fetch,git checkout,git rebase,npm install,pnpm install,yarn install, andbun installthroughout theSKILL.mdinstructions. Theinstall.shscript also executes filesystem commands likemkdirandln.
Audit Metadata