gitlab-ci-validator

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses subprocess.run inside its test suite (tests/test_validators.py) to orchestrate and execute regression tests against its own local Python validator scripts. It safely avoids passing shell=True and only processes hardcoded python script paths and text inputs generated during test execution, representing a standard and safe automated testing paradigm.
  • [EXTERNAL_DOWNLOADS]: The environment setup script (scripts/install_tools.sh) and python wrapper (scripts/python_wrapper.sh) utilize standard package managers (npm and pip) to install well-known technologies (gitlab-ci-local and pyyaml) from authoritative public registries. These are standard tooling setups and contain no malicious or unverified remote resource dependencies.
  • [PRIVILEGE_ESCALATION]: The skill requests standard file executable modifications (chmod +x) in SKILL.md strictly on its own static scripts to enable local routing. It does not perform overly permissive modifications on external data files or request unauthorized elevated shell execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:24 PM