triage-dependencies

Installation
SKILL.md

Skill: Triage Dependencies

Read the project's dependency libraries and flag the ones that can introduce a taint source — a place untrusted data enters

Inputs

Provided by the caller, fall back to the default value when omitted. Ask back only when a required input is missing and has no sensible default

  • project-root (optional) — root of the target project. Opentaint keeps all analysis artifacts under the fixed <project-root>/.opentaint/ directory, so every .opentaint/... path below resolves there. Default: current directory

Workflow

1. List the dependencies

Read .opentaint/project/project.yaml — the dependencies list under each per-language projects entry is every third-party dependency the model resolved. Resolve each to the library it is. Most of a large project's dependencies are transitive infrastructure

2. Mark each library

For each library decide: could it introduce an attacker-controlled source — a method returning untrusted data (HTTP/RPC request data, message-broker payloads, deserialized untrusted input and so on)? Judge by the library's identity itself, read sources to get overviews, docs

Installs
55
Repository
seqra/opentaint
GitHub Stars
157
First Seen
Jun 11, 2026
triage-dependencies — seqra/opentaint