lov-gh-tidy

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses gh and git command-line interfaces for repository management. These commands (e.g., gh issue close, gh pr merge, git push origin --delete) are standard for the intended workflow and are only executed following user-approved triage decisions.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted input from GitHub issues and PRs. The risk of the agent following instructions embedded in issue titles or PR bodies is mitigated by a mandatory human-in-the-loop triage process. The agent is required to present an analysis of each item to the user and obtain explicit confirmation via AskUserQuestion before performing any write operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:07 PM
Security Audit — agent-trust-hub — lov-gh-tidy