workflow
Fail
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill provides installation instructions (
curl -sS https://webi.sh/gh | sh) that download and execute code from an external server directly in the system shell. This pattern allows for the execution of unverified remote code from a third-party source without integrity checks or local auditing. - [EXTERNAL_DOWNLOADS]: The skill references an installer from
webi.sh, which is an external entity not identified as a trusted vendor or official distribution channel for the GitHub CLI. - [COMMAND_EXECUTION]: The skill uses the GitHub CLI (
gh) to execute shell-based operations including managing CI/CD runs, viewing logs, and downloading files, which involve interactions with the network and local operating system. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of raw logs from GitHub Actions via the
gh run view --logcommand. Because logs can contain output from any process running in the CI environment, they represent an attack surface where a malicious actor could embed instructions designed to influence the behavior of the agent reading the log. - Ingestion points: GitHub Action logs retrieved via
gh run viewas referenced inSKILL.md. - Boundary markers: Absent; log output is ingested as raw text.
- Capability inventory: File system writing via
gh run downloadand workflow control viagh run rerunandgh workflow run. - Sanitization: Absent; the skill does not implement any filtering or escaping for content retrieved from logs.
Recommendations
- HIGH: Downloads and executes remote code from: https://webi.sh/gh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata