skills/mabhub/skills/gitlab-api/Gen Agent Trust Hub

gitlab-api

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill includes a robust 'Security safeguards' section. It instructs the agent to never display raw GitLab tokens or session cookies and to mask sensitive values like 'private_token' or 'secret' in API responses using asterisks.
  • [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as curl and jq to interact with GitLab endpoints. All examples use environment variables (e.g., $GITLAB_TOKEN) for authentication, which avoids the risk of credential exposure in shell history or logs.
  • [SAFE]: It implements a granular permission and confirmation model. Operations are classified into 'Lecture' (Read), 'Écriture' (Write), 'Modification', and 'Destructive'. It mandates full body disclosure and user confirmation for any operation that changes state, while prohibiting critical destructive actions entirely.
  • [SAFE]: The instructions include safety guidelines against metadata poisoning and exfiltration by requiring the agent to audit output for patterns matching private keys or GitLab access tokens before displaying them to the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 03:25 PM
Security Audit — agent-trust-hub — gitlab-api