github-deep-review
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell commands to interact with GitHub and the local repository.
- Evidence: Execution of
gh,git, andrgfor metadata retrieval, diff analysis, and code searching (SKILL.md). - [INDIRECT_PROMPT_INJECTION]: The skill ingests external content from GitHub which could potentially contain malicious instructions.
- Ingestion points: GitHub issue and pull request data fetched via
gh issue view,gh pr view, andgh pr diff(SKILL.md). - Boundary markers: No explicit delimiters or instructions to ignore nested content are present.
- Capability inventory: Shell execution capabilities via
gh,git, andrg(SKILL.md). - Sanitization: No sanitization of external GitHub content is mentioned.
Audit Metadata