What the reviewer found
This skill walks the agent through setting up the user's own GitHub authentication (personal access token, new SSH key, or gh CLI) so it can push and call the API on the user's behalf. All network calls target github.com/api.github.com, the ssh-keygen line creates a new key rather than reading an existing one, and the text explicitly says no sudo is needed for this path.
credential-access— reads credentialsnetwork— calls the vendor’s API
What was read
The file as it ships in davidtoby/agent-skills:
skills/github/github-auth/SKILL.md
What the static scan said
The scan flagged 4things. The reviewer kept 0 and dismissed 4 as false.
E3Enumerates the file system for secrets — false positivePE2Asks for root — false positivePE3Reaches for credential files — false positiveNETMakes network calls — false positive
How this review was made
Sonnet 5 read the files above on 7 September 2026 and answered three questions: is it dangerous to whoever installs it, is each scanner finding real, and what should the installer know. The verdict is bound to the file's hash; when the file changes, it is scanned afresh and reviewed again. A script that changes while the definition does not is not re-reviewed — that is a known gap. How the scan and the review work.