claude-code
Warn
Audited by Socket on Aug 22, 2026
1 alert found:
AnomalyAnomalyreferences/cicd-gitlab.md
LOWAnomalyLOW
references/cicd-gitlab.md
This CI/CD integration does not show explicit malicious code, but it materially increases supply-chain and governance risk: it sends repository/CI context to an external AI service and, critically, can automatically modify code and push commits back to the branch on CI failure. Treat this as a high-impact integrity and privacy review item, and enforce strict controls (branch protections, protected variables, runner permissions, human approval gates, and tight artifact access).
Confidence: 65%Severity: 62%
Audit Metadata