pr-evidence-capture
Warn
Audited by Gen Agent Trust Hub on Jul 12, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes
gh(GitHub CLI) commands and a customgh imageextension to interact with Pull Requests and upload images. It also runs a local Python scriptscripts/verify-shot-diff.pyto compare file hashes. - [CREDENTIALS_UNSAFE]: In
references/commands.md, the skill provides instructions for usinggh image extract-tokento retrieve session tokens from a browser and suggests using theGH_SESSION_TOKENenvironment variable. While these are presented as troubleshooting steps for thegh imageextension, providing workflows for extracting and handling session tokens involves sensitive credential management.
Audit Metadata