gitlab-copilot

Warn

Audited by Socket on Mar 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: purpose and GitLab-centric capabilities mostly align, and the external CLI provenance appears official. The main risk comes from transitive delegation to another skill plus autonomous repo actions and processing of untrusted MR content that can lead to code changes, pushes, comments, approvals, and pipeline retries. Not malicious on its face, but higher-risk than a simple read-only GitLab helper.

Confidence: 89%Severity: 74%
Audit Metadata
Analyzed At
Mar 23, 2026, 02:37 AM
Package URL
pkg:socket/skills-sh/Jojious%2Fada-skills%2Fgitlab-copilot%2F@aa4518060d3fa68ff46f34c6ac5439d8de9f0181
Security Audit — socket — gitlab-copilot