github-ops
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill relies on the official GitHub CLI (gh), a tool from a well-known service provider, for all repository operations.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from external sources.\n
- Ingestion points: Reads issue descriptions, pull request metadata, and workflow logs in SKILL.md.\n
- Boundary markers: None; the instructions do not include delimiters to isolate untrusted content from the instruction context.\n
- Capability inventory: The agent can perform write actions such as commenting on issues, editing labels, and creating releases via the gh CLI.\n
- Sanitization: There are no instructions for sanitizing or validating content retrieved from GitHub before processing.
Audit Metadata