gh-cli
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill documents the
gh extension installcommand, which allows downloading and executing third-party extensions from GitHub repositories. While GitHub is a well-known service, these extensions are authored by arbitrary users and represent a potential execution vector for untrusted code. - [REMOTE_CODE_EXECUTION]: The
gh workflow runcommand is documented, which triggers execution of GitHub Actions workflows on remote infrastructure. - [COMMAND_EXECUTION]: The skill documents
gh alias setwith the!prefix or--shellflag. This allows for the creation of command aliases that execute arbitrary shell expressions through the system'sshinterpreter. - [COMMAND_EXECUTION]: The
gh codespace cpcommand with the--expandflag is documented. This treats arguments as Bash expressions to be evaluated on the remote codespace machine. The skill correctly includes a warning from the official documentation regarding the security risks of using this flag with untrusted input. - [CREDENTIALS_UNSAFE]: The
gh auth status --show-tokencommand is documented, which displays GitHub authentication tokens in plain text in the terminal output. - [INDIRECT_PROMPT_INJECTION]: The skill provides numerous workflows for reading remote repository content into the agent's context (e.g.,
gh repo read-file,gh api ... contents,gh gist view). - Ingestion points: Files fetched from remote GitHub repositories or Gists (SKILL.md, references/remote-analysis.md).
- Boundary markers: None are specified in the instructions to prevent the agent from following instructions embedded in the fetched files.
- Capability inventory: The skill provides full shell access to the
ghtool, including network operations and repository modification capabilities. - Sanitization: There are no instructions for validating or sanitizing the content retrieved from remote sources before it is processed by the agent.
Audit Metadata