skills/x-cmd/skill/gh/Gen Agent Trust Hub

gh

Pass

Audited by Gen Agent Trust Hub on Apr 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes the x-cmd ecosystem's gh module for legitimate GitHub management tasks. The core principles emphasize token initialization and using native GitHub capabilities.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface as it processes external data from GitHub. Ingestion points: GitHub issues and pull request data are read via commands like 'x gh pr ls'. Boundary markers: Absent; there are no delimiters for external content. Capability inventory: The agent can manage repositories and secrets via 'x gh'. Sanitization: Absent; external content is not sanitized before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 10, 2026, 05:40 AM
Security Audit — agent-trust-hub — gh