github-ops
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection attacks because it ingests and processes untrusted data from external sources.
- Ingestion points: The agent reads content from issue titles, bodies, and comments (
gh issue list), pull request details (gh pr view), and CI/CD logs (gh run view). - Boundary markers: There are no explicit instructions or delimiters used to prevent the agent from following instructions embedded within the processed GitHub data.
- Capability inventory: The skill utilizes the
ghCLI to perform write operations, including modifying labels (gh issue edit), posting comments (gh issue comment), creating releases (gh release create), and executing API calls (gh api). - Sanitization: No sanitization or filtering of the ingested GitHub content is performed before processing or interpolation.
- [COMMAND_EXECUTION]: The skill relies on the
ghCLI tool to perform repository operations, including issue triage, PR management, and security monitoring. While these are legitimate administrative tasks, they provide a broad capability surface for interacting with the GitHub API and repository state.
Audit Metadata