github
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runinscripts/github_client.pyto execute Git and GitHub CLI (gh) commands. This is the primary function of the skill and includes a mechanism to redact theGITHUB_TOKENfrom error output to prevent credential exposure during failed operations. - [INDIRECT_PROMPT_INJECTION]: The skill interacts with untrusted external data, specifically GitHub issue bodies and pull request review comments.
- Ingestion points: Issue bodies (processed for dependency tracking in
scripts/github_client.py) and PR review threads (handled via GraphQL as described inSKILL.md). - Boundary markers: The
SKILL.mdfile explicitly instructs the agent to "Critically evaluate each review comment before acting on it" and provides criteria for implementation, mitigating the risk of following malicious instructions in PR feedback. - Capability inventory: The skill can execute shell commands, write to the filesystem, and push changes to remote repositories.
- Sanitization: Authentication tokens are automatically redacted from command output logs to prevent exposure.
- [EXTERNAL_DOWNLOADS]: The skill interacts with the GitHub API (
api.github.com) and GitHub repositories. These operations utilize well-known services and are core to the skill's intended functionality.
Audit Metadata