github-solution-research

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (gh) to perform searches and inspect repository metadata (e.g., gh search issues, gh repo view). These commands are used solely for information retrieval from a trusted service and align with the skill's stated purpose.
  • [EXTERNAL_DOWNLOADS]: The skill fetches configuration patterns, documentation, and metadata from GitHub's official services. These operations are documented neutrally as they target a well-known technology service and do not involve the execution of untrusted remote scripts.
  • [PROMPT_INJECTION]: The skill acknowledges an indirect prompt injection surface when processing untrusted content from GitHub (such as repository READMEs or issue comments). It mitigates this risk through explicit instructions to avoid large verbatim excerpts, check licenses, and perform manual verification of all recommended solutions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 05:57 AM
Security Audit — agent-trust-hub — github-solution-research