skills/yldgio/anomalyco/gh-cli/Gen Agent Trust Hub

gh-cli

Pass

Audited by Gen Agent Trust Hub on Mar 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: Provides a detailed reference of shell commands for the gh tool, enabling operations such as repository creation, issue management, and workflow execution.
  • [EXTERNAL_DOWNLOADS]: Fetches installation packages and security keys from GitHub's official domains (cli.github.com). It also documents the gh extension install command, which allows for the addition of community-created tool extensions.
  • [PROMPT_INJECTION]: The tool described in the skill is designed to process external data (such as GitHub issues, pull requests, and search results) which could theoretically contain adversarial content. The skill provides proactive guidance on sanitizing user input and securely using templates to mitigate potential injection risks.
  • [CREDENTIALS_UNSAFE]: Documents the management of sensitive authentication tokens and SSH/GPG keys. The skill includes a dedicated 'Security Best Practices' section that advises against plain-text storage and recommends the use of scoped tokens and environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 30, 2026, 03:19 AM
Security Audit — agent-trust-hub — gh-cli