gh-plan-issues

Pass

Audited by Gen Agent Trust Hub on Jun 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates on a repository (Hmbown/CodeWhale) associated with the skill's author (hmbown), which is consistent with its stated purpose of managing project milestones.
  • [SAFE]: Command execution is limited to standard development tools (git, gh, rg, cargo) and is used for gathering evidence and verifying mergeability on the local machine.
  • [SAFE]: The skill proactively addresses the risk of Indirect Prompt Injection by including a 'Red flags' section that warns the agent to treat all issue and PR text as untrusted data rather than instructions.
  • [SAFE]: No patterns of data exfiltration, credential theft, or code obfuscation were identified. The skill is restricted to generating a local plan file (plan.md) and explicitly forbids writing back to GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 25, 2026, 12:01 PM
Security Audit — agent-trust-hub — gh-plan-issues