devops-gitlab-ci

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Security
SecurityMEDIUM
references/gitlab-runners.md

No explicit malicious code is present in this configuration fragment; however, it contains severe plaintext credentials (GitLab runner registration token and multiple cloud cache authentication secrets, including a private key). This is a critical supply-chain operational risk because leaked values can enable unauthorized access to runner registration and external cache backends, potentially facilitating runner impersonation, cache poisoning, and downstream CI/CD compromise. All exposed secrets should be treated as compromised and rotated immediately, and secrets should be removed from source-controlled configuration and stored in a dedicated secret manager with strict access controls.

Confidence: 78%Severity: 91%
Audit Metadata
Analyzed At
Aug 4, 2026, 05:20 AM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Fdevops-gitlab-ci%2F@d1df2a60715e78cdf9d6d74a43fb27ce4e67988e3753c79d55a4f1abf3dee187
Security Audit — socket — devops-gitlab-ci