gitlab-api
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [SAFE]: The skill includes a robust 'Security safeguards' section. It instructs the agent to never display raw GitLab tokens or session cookies and to mask sensitive values like 'private_token' or 'secret' in API responses using asterisks.
- [COMMAND_EXECUTION]: The skill utilizes standard command-line tools such as
curlandjqto interact with GitLab endpoints. All examples use environment variables (e.g., $GITLAB_TOKEN) for authentication, which avoids the risk of credential exposure in shell history or logs. - [SAFE]: It implements a granular permission and confirmation model. Operations are classified into 'Lecture' (Read), 'Écriture' (Write), 'Modification', and 'Destructive'. It mandates full body disclosure and user confirmation for any operation that changes state, while prohibiting critical destructive actions entirely.
- [SAFE]: The instructions include safety guidelines against metadata poisoning and exfiltration by requiring the agent to audit output for patterns matching private keys or GitLab access tokens before displaying them to the user.
Audit Metadata