github-cli
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPRIVILEGE_ESCALATIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill documents the official Linux installation process which involves downloading a GPG keyring from cli.github.com to verify package integrity. This follows GitHub's recommended security practices for repository setup.
- [COMMAND_EXECUTION]: Provides instructions for configuring shell aliases and git credential helpers (e.g., 'gh auth setup-git'). these are standard operations for integrating the GitHub CLI into a developer's workflow.
- [PRIVILEGE_ESCALATION]: Includes installation commands using 'sudo' for adding the official GitHub package repository and installing the CLI on Linux systems, which is the standard procedure for system-wide software installation.
- [DYNAMIC_EXECUTION]: References the use of 'eval' to load shell completion scripts (e.g., 'eval "$(gh completion -s bash)"'). This is the standard method for enabling interactive command-line features for the gh tool.
- [REMOTE_CODE_EXECUTION]: Documents the 'gh extension install' command, which is a native feature of the GitHub CLI for adding subcommands from external repositories. Users should ensure they trust the extension authors before installation.
Audit Metadata