pp-github

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install a CLI tool (github-pp-cli) and an MCP server (github-pp-mcp) from the author's official GitHub repository (github.com/mvanhorn/printing-press-library) and via NPM (@mvanhorn/printing-press-library). These sources are consistent with the skill author's identity and represent standard distribution methods for such tools.
  • [COMMAND_EXECUTION]: The skill is designed to execute the github-pp-cli binary with various subcommands to interact with GitHub data. This includes local mirroring of repositories and performing searches. The use of the --agent flag is documented to streamline machine-readable output.
  • [CREDENTIALS_UNSAFE]: The documentation mentions the use of GITHUB_TOKEN or GH_TOKEN environment variables for authentication with GitHub. It correctly advises users to use Personal Access Tokens (PATs) and highlights that read-only scopes are sufficient for many operations. It does not contain hardcoded secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 12:30 AM
Security Audit — agent-trust-hub — pp-github