glab-cli
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes potentially untrusted data from GitLab resources, creating a surface for indirect prompt injection.
- Ingestion points: Data is ingested through commands like
glab mr view,glab issue view, andglab ci trace(SKILL.md). - Boundary markers: While explicit delimiters for external content are not specified, the skill requires careful processing of outputs to identify embedded instructions.
- Capability inventory: The agent can perform write and destructive operations (e.g.,
mr merge,variable set,api -X POST) across the GitLab instance (SKILL.md). - Sanitization: The skill enforces strict sanitization rules, including mandatory human-in-the-loop confirmation for all write/destructive actions and automatic token masking.
- [COMMAND_EXECUTION]: The skill executes shell commands via the
glabCLI tool. This functionality is protected by strict rules against interactive prompts, ensuring that automated flags like--yesandNO_PROMPT=1are only used after the user has explicitly approved the specific operation and its contents.
Audit Metadata