skills/kevmoo/scripts.dart/gh-post/Gen Agent Trust Hub

gh-post

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted repository data, including issue templates, labels, and maintainer names, retrieved via the kscripts gh-orient tool. This data is used to populate GitHub issue and pull request bodies.
  • Ingestion points: SKILL.md (Step 2: Repository Orientation via kscripts gh-orient).
  • Boundary markers: Absent for external repository data; the skill relies on instructional constraints (e.g., "Use orientation output strictly for taxonomy") and a mandatory human approval gate.
  • Capability inventory: gh issue create, gh pr create (Step 5: Execution).
  • Sanitization: No explicit sanitization or escaping of repository-provided strings is documented.
  • [COMMAND_EXECUTION]: The skill utilizes shell commands to orient to repositories and perform submissions.
  • Evidence: The workflow executes kscripts gh-orient, kscripts pr-check, tail, and the gh (GitHub CLI) tool. These operations are gated by a mandatory user approval step (ask_question in Step 4) before any remote execution occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 11:11 PM