github-ops

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill relies on the official GitHub CLI (gh), a tool from a well-known service provider, for all repository operations.\n- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it ingests untrusted data from external sources.\n
  • Ingestion points: Reads issue descriptions, pull request metadata, and workflow logs in SKILL.md.\n
  • Boundary markers: None; the instructions do not include delimiters to isolate untrusted content from the instruction context.\n
  • Capability inventory: The agent can perform write actions such as commenting on issues, editing labels, and creating releases via the gh CLI.\n
  • Sanitization: There are no instructions for sanitizing or validating content retrieved from GitHub before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:09 PM