lov-gh-access
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes GitHub API calls through the
ghCLI to list, grant, and revoke repository access. These commands incorporate parameters such as repository names and user identifiers supplied by the user during interaction. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted input in the form of GitHub usernames and email addresses which are then used to interact with the GitHub API.
- Ingestion points: The skill uses
AskUserQuestionto collect a list of identifiers (usernames/emails) and target repositories from the user. - Boundary markers: The skill requires the agent to display a resolution table and obtain explicit confirmation before performing any write or delete operations, reducing the risk of accidental or malicious identifier execution.
- Capability inventory: The skill uses the
gh apitool to perform GET, PUT, and DELETE operations on GitHub resources. - Sanitization: The instructions include a resolution step where identifiers are verified against the GitHub
users/API before access is granted, effectively validating the identifier against known GitHub accounts.
Audit Metadata