gh-stack

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill automates the installation of the github/gh-stack extension using the GitHub CLI (gh extension install github/gh-stack). This targets the official repository of a well-known service and organization.
  • [COMMAND_EXECUTION]: The instructions utilize git and gh commands for repository management. The skill provides clear instructions for non-interactive usage, including using the --json flag for machine-readable state analysis and --auto or --yes flags to bypass interactive prompts, ensuring predictable behavior in automated environments.
  • [PROMPT_INJECTION]: The skill contains a safety rule specifying that the agent must never merge a stack without explicit user approval. This instruction serves as a safety guardrail to prevent unintended repository modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:34 AM
Security Audit — agent-trust-hub — gh-stack