github

Warn

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of the gh (GitHub CLI) tool to perform operations such as creating issues, viewing PR checks, and listing workflow runs.
  • [CREDENTIALS_UNSAFE]: The instruction set includes the gh auth token command. When executed, this command prints the active GitHub authentication token directly into the agent's context, which could lead to accidental exposure in session logs or intentional exfiltration.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external, untrusted sources on GitHub (issue bodies, PR comments, and CI/CD logs).
  • Ingestion points: Commands such as gh issue view, gh pr checks, gh run view, and gh api fetch content from GitHub repositories (documented in SKILL.md and github/SKILL.md).
  • Boundary markers: No delimiters or safety instructions are provided to help the agent distinguish between its own instructions and the content retrieved from GitHub.
  • Capability inventory: The skill possesses the ability to execute CLI commands and interact with the GitHub API.
  • Sanitization: There is no evidence of filtering or sanitization of the external data before it is presented to the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 18, 2026, 06:13 AM
Security Audit — agent-trust-hub — github