gh-cli
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill includes instructions to fetch the official GitHub CLI signing key and repository configuration from
cli.github.comduring the installation process. - [COMMAND_EXECUTION]: The documentation provides standard shell commands for package installation using
brew,apt(utilizingsudo), andwinget, as well as the full suite ofghCLI commands for repository, secret, and account management. - [INDIRECT_PROMPT_INJECTION]: The skill documents commands that ingest untrusted content from external sources (such as GitHub issue bodies, pull request descriptions, and comments) into the agent's context, creating a potential attack surface if the agent acts on instructions embedded within that data.
- Ingestion points: Commands like
gh issue view,gh pr view, andgh gist viewfetch user-generated content from GitHub (SKILL.md). - Boundary markers: None identified in the instructional text.
- Capability inventory: The skill documents capabilities for repository deletion (
gh repo delete), secret management (gh secret set), and workflow execution (gh workflow run). - Sanitization: None present; the skill functions as a static command reference.
Audit Metadata