merge-dependabot-prs
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Analysis of the skill's interaction with the GitHub CLI (
gh) andgitconfirms that commands are executed using structured argument lists. This approach avoids the risks associated with shell interpolation of user input. The command usage is appropriate for the skill's functionality. - [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests pull request titles, commit messages, and release notes from GitHub. The skill incorporates multiple defensive measures: it specifically filters for pull requests from the official Dependabot application, performs serial processing, and requires a user review of the merge plan before execution.
- [DYNAMIC_EXECUTION]: The
dependabot_prs.pyscript usessubprocess.runto call external binaries. The implementation uses explicit argument lists and does not involve runtime compilation or the execution of code from untrusted sources. - [DATA_EXFILTRATION]: The network activity observed is restricted to standard GitHub CLI operations for repository metadata management. There is no evidence of attempts to access sensitive credentials or exfiltrate data to unauthorized third-party domains.
Audit Metadata