gitlab-ci-review
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: This skill possesses an attack surface for indirect prompt injection as it is designed to ingest and process external, potentially untrusted data such as Merge Request comments and GitLab CI scripts.
- Ingestion points: Files located within the
ci/directory, project shell scripts, jq filters, and GitLab Merge Request comments. - Boundary markers: The instructions do not specify explicit delimiters or guardrails to distinguish between agent instructions and the data being reviewed.
- Capability inventory: The skill instructs the agent to read and analyze file contents and formatting behavior.
- Sanitization: There are no mentions of sanitization, filtering, or escaping mechanisms for the processed content.
Audit Metadata