github-issue-workflow

Pass

Audited by Gen Agent Trust Hub on May 10, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The helper script scripts/issue_pr_closeout.py automates interactions with the GitHub CLI (gh) and git. These commands are constructed using list-based arguments for subprocess.run() and do not use a shell, following secure coding practices to prevent shell injection.\n- [SAFE]: The skill provides strong preventative guidance in references/external-dependency-research.md and SKILL.md, instructing users and agents never to store actual secrets or API keys in GitHub issues. It promotes recording only metadata and retrieval paths.\n- [SAFE]: The skill ingests and parses external data from GitHub issues and comments to track progress via checklists. While this is an indirect prompt injection surface, the skill treats the content as data for state reconciliation rather than as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 10, 2026, 02:22 AM