github
Warn
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: MEDIUMCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of the
gh(GitHub CLI) tool to perform operations such as creating issues, viewing PR checks, and listing workflow runs. - [CREDENTIALS_UNSAFE]: The instruction set includes the
gh auth tokencommand. When executed, this command prints the active GitHub authentication token directly into the agent's context, which could lead to accidental exposure in session logs or intentional exfiltration. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it processes data from external, untrusted sources on GitHub (issue bodies, PR comments, and CI/CD logs).
- Ingestion points: Commands such as
gh issue view,gh pr checks,gh run view, andgh apifetch content from GitHub repositories (documented inSKILL.mdandgithub/SKILL.md). - Boundary markers: No delimiters or safety instructions are provided to help the agent distinguish between its own instructions and the content retrieved from GitHub.
- Capability inventory: The skill possesses the ability to execute CLI commands and interact with the GitHub API.
- Sanitization: There is no evidence of filtering or sanitization of the external data before it is presented to the agent.
Audit Metadata