gitlab-ci-validator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
subprocess.runinside its test suite (tests/test_validators.py) to orchestrate and execute regression tests against its own local Python validator scripts. It safely avoids passingshell=Trueand only processes hardcoded python script paths and text inputs generated during test execution, representing a standard and safe automated testing paradigm. - [EXTERNAL_DOWNLOADS]: The environment setup script (
scripts/install_tools.sh) and python wrapper (scripts/python_wrapper.sh) utilize standard package managers (npmandpip) to install well-known technologies (gitlab-ci-localandpyyaml) from authoritative public registries. These are standard tooling setups and contain no malicious or unverified remote resource dependencies. - [PRIVILEGE_ESCALATION]: The skill requests standard file executable modifications (
chmod +x) inSKILL.mdstrictly on its own static scripts to enable local routing. It does not perform overly permissive modifications on external data files or request unauthorized elevated shell execution.
Audit Metadata