github
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external GitHub resources such as issues, pull requests, and workflow logs.\n
- Ingestion points: Data is pulled into the environment through
gh issue,gh pr,gh run, andgh apicommands.\n - Boundary markers: There are no explicit instructions or delimiters provided to the agent to treat external content as untrusted data or to ignore embedded instructions.\n
- Capability inventory: The skill has the capability to execute
ghCLI commands and perform network operations via the GitHub API.\n - Sanitization: The skill does not implement specific sanitization or validation of the content retrieved from GitHub before it is processed by the agent.\n- [COMMAND_EXECUTION]: The skill's primary function is to execute shell commands using the GitHub CLI (
gh) to perform repository management tasks.\n- [EXTERNAL_DOWNLOADS]: The skill configuration includes metadata for installing the official GitHub CLI tool via standard system package managers such as Homebrew (brew) and APT.
Audit Metadata