gh-plan-issues
Pass
Audited by Gen Agent Trust Hub on Jun 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates on a repository (
Hmbown/CodeWhale) associated with the skill's author (hmbown), which is consistent with its stated purpose of managing project milestones. - [SAFE]: Command execution is limited to standard development tools (
git,gh,rg,cargo) and is used for gathering evidence and verifying mergeability on the local machine. - [SAFE]: The skill proactively addresses the risk of Indirect Prompt Injection by including a 'Red flags' section that warns the agent to treat all issue and PR text as untrusted data rather than instructions.
- [SAFE]: No patterns of data exfiltration, credential theft, or code obfuscation were identified. The skill is restricted to generating a local plan file (
plan.md) and explicitly forbids writing back to GitHub.
Audit Metadata