gitlab

Warn

Audited by Socket on Jun 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's GitLab purpose is plausible, but its actual footprint depends on a third-party hosted gateway and credential model rather than direct GitLab APIs. The npm-delivered CLI appears project-associated rather than a random payload, so this is not confirmed malware; however, credential brokerage through ClawLink, local credential storage, unpinned `npx` execution, and high-impact GitLab actions make the overall risk medium-high.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Jun 28, 2026, 02:44 PM
Package URL
pkg:socket/skills-sh/clawlink-hq%2Fskills%2Fgitlab%2F@5dc9f77bcc2c4a221fc7ee632185f6910745a308de8f17cdf70446f5fd005b43
Security Audit — socket — gitlab