gh-cli

Fail

Audited by Snyk on Aug 19, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill includes a literal ghp_... token example and commands that print or reveal tokens (gh auth token, gh auth status --show-token, gh auth login --with-token), which would force an agent to handle or expose secret values verbatim if followed or echoed in output.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). The runtime workflow (via gh issue view/--comments, gh pr view/--comments, gh run view/--log, etc.) can ingest outsider-authored free text from GitHub issue/PR bodies and comments when viewing specific items.

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.70). The skill includes explicit sudo commands that write to system locations (/usr/share/keyrings, /etc/apt/sources.list.d) and run apt install, which instructs obtaining root privileges and modifying system files.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W013
MEDIUM

Attempt to modify system services in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 19, 2026, 05:31 PM
Issues
3
Security Audit — snyk — gh-cli