gitlab-code-review

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious instructions, safety bypasses, or attempts to override agent behavior were detected. The instructions provide constructive behavioral guidelines for performing code reviews.\n- [DATA_EXFILTRATION]: The skill interacts exclusively with a self-hosted GitLab instance (https://gitlab-erp-pas.dedalus.lan) belonging to the vendor. No data exfiltration to unauthorized external domains was identified.\n- [REMOTE_CODE_EXECUTION]: No patterns of remote code execution, piped shell commands, or dynamic code generation from untrusted sources were found.\n- [COMMAND_EXECUTION]: The skill uses a predefined set of tools through the gitlab-mcp server. No arbitrary shell command execution or unauthorized system access was detected.\n- [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or other sensitive credentials were found. The skill relies on externally configured access for the GitLab instance.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 02:39 PM
Security Audit — agent-trust-hub — gitlab-code-review