cyrus-setup-gitlab

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that use imperative language ("CRITICAL: Never use...") to override the agent's default behavior regarding tool usage for specific file paths. While this is intended as a safety measure to prevent secrets from entering the conversation context, instructions designed to mandate or bypass standard tool procedures are analyzed for potential behavior override patterns.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection by taking user-supplied strings and placing them directly into shell commands.
  • Ingestion points: The agent is instructed to ask the user for a name and email in Step 3.
  • Boundary markers: No delimiters or safety instructions are used when interpolating these values into the shell command.
  • Capability inventory: The skill utilizes Bash capabilities to execute git config and glab commands.
  • Sanitization: There is no evidence of sanitization or validation for the user-provided strings before they are executed in the shell.
  • [COMMAND_EXECUTION]: The skill performs shell command execution to configure glab (GitLab CLI) and git. These operations are consistent with the skill's stated purpose of setting up a development environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:14 AM
Security Audit — agent-trust-hub — cyrus-setup-gitlab