vdb_harden
Analyze Python code to determine if user input reaches dangerous operations through transitive dependencies, without relying on CVEs. Get actionable paths, a non-invasive call-site fix, and residual risk.
Instructions
Decide whether attacker-controlled data can reach a dangerous operation through this file's transitive dependencies — with no CVE required. Use it on code that passes user input into a third-party API. The file is abstracted LOCALLY first (identifiers renamed, literals reduced to shapes, bodies dropped); only that abstraction and the lockfile are sent, never source text. Returns decided paths, a call-site fix that does not modify the dependency, and the residual risk the fix does not cover.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Python file to analyze. | |
| manifest_path | Yes | uv.lock / poetry.lock / Pipfile.lock / requirements.txt / CycloneDX. Version ranges cannot be analyzed — the answer differs per resolved version. |