kh-assistant
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill fetches project metadata and release information from the official GitHub repository using the
ghcommand-line tool. It also provides commands for users to install related skills from the same vendor organization usingnpx. - [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources, including GitHub issues and discussions. This is an inherent risk factor where untrusted content could potentially influence the agent's behavior.
- Ingestion points: GitHub issue content, discussion titles, and documentation files (SKILL.md).
- Boundary markers: None identified.
- Capability inventory: Execution of
gh,terraform,grep, andnpxcommands. - Sanitization: None identified.
Audit Metadata