skills/mabhub/skills/gh-cli/Gen Agent Trust Hub

gh-cli

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches GPG signing keys and repository configurations from the official GitHub domain (cli.github.com) during the installation process for Linux systems.
  • [COMMAND_EXECUTION]: Provides documentation for the full suite of GitHub CLI commands, including repository management, issue tracking, and workflow automation. It includes a security section that categorizes operations by risk level (Read, Write, Destructive).
  • [PROMPT_INJECTION]: Contains defensive instructions that establish safety guardrails for the agent, such as explicitly forbidding the execution of destructive commands (e.g., repository deletion) even if requested by a user.
  • [CREDENTIALS_UNSAFE]: References authentication mechanisms and environment variables (like GH_TOKEN), but uses standard placeholders or secure practices (e.g., reading from files or environment variables) rather than hardcoding sensitive data.
  • [REMOTE_CODE_EXECUTION]: Documents the 'gh extension install' and 'gh codespace ssh' features, which are standard functionalities of the GitHub CLI for extending the tool or accessing remote environments.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 04:07 PM
Security Audit — agent-trust-hub — gh-cli