gitlab

Warn

Audited by Socket on May 2, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose and capabilities mostly align, and the install source appears vendor-consistent, but all GitLab access is mediated through Membrane rather than GitLab directly. That third-party credential/data routing and dynamic remote action creation are proportionate but create medium trust and data-flow risk.

Confidence: 86%Severity: 57%
Audit Metadata
Analyzed At
May 2, 2026, 02:45 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fgitlab%2F@c79fbd371d39df4a879b2cbd99f92ebc313da96b
Security Audit — socket — gitlab