github-deep-review

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands to interact with GitHub and the local repository.
  • Evidence: Execution of gh, git, and rg for metadata retrieval, diff analysis, and code searching (SKILL.md).
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from GitHub which could potentially contain malicious instructions.
  • Ingestion points: GitHub issue and pull request data fetched via gh issue view, gh pr view, and gh pr diff (SKILL.md).
  • Boundary markers: No explicit delimiters or instructions to ignore nested content are present.
  • Capability inventory: Shell execution capabilities via gh, git, and rg (SKILL.md).
  • Sanitization: No sanitization of external GitHub content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:15 PM
Security Audit — agent-trust-hub — github-deep-review