skills/openhands/extensions/github/Gen Agent Trust Hub

github

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run in scripts/github_client.py to execute Git and GitHub CLI (gh) commands. This is the primary function of the skill and includes a mechanism to redact the GITHUB_TOKEN from error output to prevent credential exposure during failed operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted external data, specifically GitHub issue bodies and pull request review comments.
  • Ingestion points: Issue bodies (processed for dependency tracking in scripts/github_client.py) and PR review threads (handled via GraphQL as described in SKILL.md).
  • Boundary markers: The SKILL.md file explicitly instructs the agent to "Critically evaluate each review comment before acting on it" and provides criteria for implementation, mitigating the risk of following malicious instructions in PR feedback.
  • Capability inventory: The skill can execute shell commands, write to the filesystem, and push changes to remote repositories.
  • Sanitization: Authentication tokens are automatically redacted from command output logs to prevent exposure.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with the GitHub API (api.github.com) and GitHub repositories. These operations utilize well-known services and are core to the skill's intended functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — github