skills/thelobbi/claude/gh-mcp/Gen Agent Trust Hub

gh-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is an informational reference for GitHub MCP tool mapping and does not include malicious code or hidden scripts.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies PR bodies, issue bodies, and CI logs as untrusted ingestion points. It implements boundary instructions to treat these as data and mandates a human review checkpoint if content attempts to override the task.
  • [DATA_EXPOSURE]: Provides guidance on secure authentication, favoring OAuth over Personal Access Tokens to minimize exposure and using non-sensitive placeholders for examples.
  • [COMMAND_EXECUTION]: Recommends the use of Node.js for parsing large metadata files locally to avoid context limit issues.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 10:14 AM
Security Audit — agent-trust-hub — gh-mcp