github
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill serves as a guide for using the GitHub command-line interface. It demonstrates standard, non-malicious usage patterns for checking PR status, listing workflow runs, and querying the GitHub API.
- [COMMAND_EXECUTION]: The skill relies on the
ghCLI being available in the agent's environment. The instructions provide clear, bounded examples for repository management without attempting to execute arbitrary or hidden shell commands. - [INDIRECT_PROMPT_INJECTION]: As the skill is designed to ingest data from external sources like GitHub issue descriptions and workflow logs, there is an inherent surface for indirect prompt injection.
- Ingestion points: Data enters the context via
gh pr,gh issue, andgh run view(specifically in logs). - Boundary markers: None explicitly defined in the provided instructions.
- Capability inventory: The skill facilitates read operations via the CLI but does not provide scripts for automated write actions or persistent changes.
- Sanitization: Standard tool output handling is assumed; no custom sanitization is implemented within the skill instructions.
Audit Metadata