pr-github-ops
Pass
Audited by Gen Agent Trust Hub on Jun 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill guides the agent to use the
ghCLI and standard Unix utilities (sed,tr,sha256sum,awk) to interact with the GitHub API and calculate content fingerprints for deduplication. - [EXTERNAL_DOWNLOADS]: The skill interacts with the GitHub API (a well-known service) via the
ghtool to fetch PR diffs, file lists, and existing comments. These operations are within the expected scope of a GitHub integration tool. - [PROMPT_INJECTION]: No patterns of prompt injection or instructions to bypass safety guidelines were detected in the skill's content.
- [DATA_EXFILTRATION]: Data transfer is limited to the authenticated GitHub API of the repository being scanned. No unauthorized or suspicious third-party domains are contacted.
Audit Metadata