ghpm-view
Pass
Audited by Gen Agent Trust Hub on Mar 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected in the skill's instructions or workflow. The tool operates as a read-only viewer for GitHub Projects.\n- [COMMAND_EXECUTION]: The skill uses the GitHub CLI (
gh) via Bash to retrieve project data. Access is restricted to tools necessary for its stated purpose.\n- [PROMPT_INJECTION]: No prompt injection or instructions to bypass safety guidelines were found in the skill definitions or metadata.\n- [DATA_EXFILTRATION]: The skill accesses local configuration files (.ghpm/config.json) and GitHub project data, which is appropriate for its functionality. There are no attempts to send data to unauthorized external endpoints.
Audit Metadata