pr-evidence-capture

Warn

Audited by Gen Agent Trust Hub on Jul 12, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes gh (GitHub CLI) commands and a custom gh image extension to interact with Pull Requests and upload images. It also runs a local Python script scripts/verify-shot-diff.py to compare file hashes.
  • [CREDENTIALS_UNSAFE]: In references/commands.md, the skill provides instructions for using gh image extract-token to retrieve session tokens from a browser and suggests using the GH_SESSION_TOKEN environment variable. While these are presented as troubleshooting steps for the gh image extension, providing workflows for extracting and handling session tokens involves sensitive credential management.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 12, 2026, 09:11 AM
Security Audit — agent-trust-hub — pr-evidence-capture