Review recommended
Independent security partners scan this skill's files for malicious content, prompt injection and risky patterns. Verdicts below come from the skills.sh audit program; each partner links to its full report.
Gen Agent Trust Hub
passThe skill facilitates GitHub contribution workflows using the gh CLI. It is well-designed with security best practices, including mandatory user confirmation and robust shell quoting. It has a minor vulnerability surface for indirect prompt injection, common to tools that process external content.
Socket
passNo alerts
Snyk
warnRisk: MEDIUM · 2 issues
Runlayer
warn10/10 files flagged
ZeroLeaks
passScore: 93/100 · 2 sections analyzed