gitlab
Warn
Audited by Socket on Jun 28, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's GitLab purpose is plausible, but its actual footprint depends on a third-party hosted gateway and credential model rather than direct GitLab APIs. The npm-delivered CLI appears project-associated rather than a random payload, so this is not confirmed malware; however, credential brokerage through ClawLink, local credential storage, unpinned `npx` execution, and high-impact GitLab actions make the overall risk medium-high.
Confidence: 86%Severity: 68%
Audit Metadata