keep
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) via thesubprocessmodule inscripts/github_sync.pyto interact with remote repositories. Commands are executed using argument lists rather than shell strings, which is a recommended security practice to prevent shell injection. - [EXTERNAL_DOWNLOADS]: The skill fetches issue descriptions, titles, and labels from GitHub to populate local work tracking files in the
.claude/directory. These downloads are directed to the official GitHub API via theghtool. - [DATA_EXFILTRATION]: Local work summaries, technical decisions, and progress updates are posted back to GitHub issues as comments. This data transmission is a documented core feature intended to keep remote project boards synchronized with local development progress.
- [SAFE]: No obfuscation techniques, hardcoded credentials, or unauthorized persistence mechanisms were detected. All file operations are restricted to the local project environment and the standard
.claude/configuration directory.
Audit Metadata