Security
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Independent checks from skills.sh's audit partners.
Fail5 providerslatest audit Apr 16, 2026
Independent checks from skills.sh's audit partners.
This skill provides powerful GitHub management capabilities but introduces significant security risks. It includes instructions to bypass organizational policy checks (JIRA enforcement) and is highly vulnerable to Indirect Prompt Injection. A malicious actor could embed instructions in Pull Requests or Issues that the agent might execute, leading to unauthorized code merges, secret modifications, or workflow triggers. The heavy use of shell pipes and xargs also increases the risk of command injection from untrusted data.
Detected behaviors
No alerts
No issues
5/6 files flagged
Score: 93/100 · 2 sections analyzed