Skip to content

chore(deps): update trailofbits/skills digest to d1f1575 - #927

Open
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/trailofbits-skills-digest
Open

chore(deps): update trailofbits/skills digest to d1f1575#927
renovate[bot] wants to merge 2 commits into
mainfrom
renovate/trailofbits-skills-digest

Conversation

@renovate

@renovate renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
trailofbits/skills digest 7b9bd5fd1f1575

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

…onstant-time-analysis,differential-review,fp-check,property-based-testing,sarif-parsing,semgrep,semgrep-rule-creator,semgrep-rule-variant-creator,sharp-edges,supply-chain-risk-auditor,variant-analysis,yara-rule-authoring,zeroize-audit
@toolhive-release-app

toolhive-release-app Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor

🛡️ Skill Security Scan Results

✅ agentic-actions-auditor

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 2
    • MANIFEST_MISSING_LICENSE (Allowed: trailofbits/skills is licensed CC-BY-SA-4.0 at the repository root; upstream does not embed a license field in per-skill SKILL.md frontmatter.)
    • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: agentic-actions-auditor is a security audit skill whose reference files intentionally describe CI/CD attack patterns (prompt injection, expression injection, subshell expansion, credential exfiltration) with PoC examples for detection purposes. All ATR pattern matches are documentation of what to detect, not agent instructions.)

❌ codeql

  • Status: Failed
  • Findings: 79
  • Blocking: 1

Blocking issues:

  • [LLM_UNAUTHORIZED_TOOL_USE] (HIGH) The default scan pipeline automatically builds a CodeQL database before analysis. For compiled languages, CodeQL database creation traces a project build, which can invoke repository-controlled build files, package-manager lifecycle hooks, generators, compiler wrappers, and scripts. The instructions do not require an explicit confirmation that the target repository is trusted and do not require sandboxing or isolation. A malicious repository submitted for scanning could therefore execute code with the agent's filesystem, environment-variable, and network access. (SKILL.md)

Allowlisted (not blocking):

  • LLM_COMMAND_INJECTION (Allowed: Risk accepted by maintainer (danbarr, 2026-08-25): workflows/build-database.md and references/macos-arm64e-workaround.md construct and execute the target codebase's own build commands (make/cmake/gradle/etc., including a make --dry-run compile-command extraction for the macOS arm64e workaround) in order to trace compilation for CodeQL database creation. Building the analyzed codebase — including running whatever build system it uses — is CodeQL's documented, required mechanism for compiled-language analysis; there is no way to trace compilation without executing the project's own build scripts. Same class of inherent domain risk as running any CI/build pipeline against the target codebase, not a new injection primitive introduced by the skill.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00032 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00111 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00040 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00012 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00012 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00066 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00040 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00066 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00040 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00066 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00066 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00084 (Allowed: FP: same as policy_violation above — all pattern matches are on documentation, code examples, or attack pattern descriptions for detection purposes, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • LLM_CONTEXT_BUDGET_EXCEEDED (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00099 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)
  • ATR_2026_00061 (Allowed: FP: codeql is a security analysis skill whose reference files contain CodeQL workflow documentation, quality assessment commands, and performance tuning examples. All ATR pattern matches are documentation of analysis procedures, not agent instructions.)

✅ constant-time-analysis

  • Status: Passed
  • Findings: 3

✅ differential-review

  • Status: Passed
  • Findings: 0

✅ fp-check

  • Status: Passed
  • Findings: 1

✅ property-based-testing

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: trailofbits/skills is licensed CC-BY-SA-4.0 at the repository root; upstream does not embed a license field in per-skill SKILL.md frontmatter.)

✅ sarif-parsing

  • Status: Passed
  • Findings: 3
  • Allowed (not blocking): 1
    • ALLOWED_TOOLS_WRITE_VIOLATION (Allowed: SKILL.md declares Bash in allowed-tools, which transitively permits filesystem writes (e.g. via redirection); the scanner flags bundled scripts as writing without recognizing Bash as the intended mechanism.)

✅ semgrep

  • Status: Passed
  • Findings: 1

✅ semgrep-rule-creator

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • LLM_PROMPT_INJECTION (Allowed: FP: same as policy_violation above — all pattern matches are on documentation, code examples, or attack pattern descriptions for detection purposes, not agent instructions.)

✅ semgrep-rule-variant-creator

  • Status: Passed
  • Findings: 1
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: trailofbits/skills is licensed CC-BY-SA-4.0 at the repository root; upstream does not embed a license field in per-skill SKILL.md frontmatter.)

✅ sharp-edges

  • Status: Passed
  • Findings: 0

✅ supply-chain-risk-auditor

  • Status: Passed
  • Findings: 0

✅ variant-analysis

  • Status: Passed
  • Findings: 1

✅ yara-rule-authoring

  • Status: Passed
  • Findings: 1

❌ zeroize-audit

  • Status: Failed
  • Findings: 4
  • Blocking: 3

Blocking issues:

  • [LLM_SUPPLY_CHAIN_ATTACK] (HIGH) Rust emitters invoke Cargo without --locked, --offline, a vetted registry configuration, or dependency provenance controls. A supplied manifest can request new registry or Git dependencies, and Cargo may fetch and compile them; dependency build scripts can execute during compilation. This expands the analysis operation into an unpinned supply-chain acquisition and execution path. (tools/emit_rust_mir.sh)
  • [LLM_UNAUTHORIZED_TOOL_USE] (HIGH) The Rust analysis helpers invoke cargo rustc and cargo check against a supplied Cargo manifest. Cargo builds can execute untrusted project-controlled build scripts, procedural macros, and compiler tooling. Because the skill is intended to analyze potentially untrusted source trees, this turns an audit operation into native-code execution in the agent environment without sandboxing, an explicit confirmation boundary, or privilege/network restrictions. (tools/emit_rust_mir.sh)
  • [LLM_COMMAND_INJECTION] (HIGH) extract_compile_flags.py extracts almost all arguments from a project-controlled compile_commands.json and emits them for direct use by the IR/assembly emitters. The filtering only removes output, dependency, and diagnostic flags. It does not reject compiler plugin-loading or code-executing options such as Clang plugin/pass-plugin options and related frontend flags. A malicious or untrusted compilation database can therefore cause the audit workflow to load attacker-controlled compiler extensions when its returned flags are replayed. (tools/extract_compile_flags.py)

Summary: Scanned 15 skill(s), found 4 blocking issue(s).

⚠️ Action Required: Review the blocking findings. Add a justified entry to the skill's security.allowed_issues[] in its spec.yaml if the finding is a false positive.

@renovate

renovate Bot commented Aug 31, 2026

Copy link
Copy Markdown
Contributor Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants