gitlab-automation

Warn

Audited by Socket on Sep 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s GitLab automation purpose matches its capabilities, and there is no direct malware pattern or executable installer. However, it relies on a third-party MCP/OAuth intermediary for all GitLab access, and the documented Rube endpoint appears outdated/discontinued, which makes install trust and data-flow integrity only partially verifiable.

Confidence: 85%Severity: 55%
Audit Metadata
Analyzed At
Sep 4, 2026, 03:05 PM
Package URL
pkg:socket/skills-sh/new-career-begin%2Fqueryweaver%2Fgitlab-automation%2F@c51c55d5331e3846b75cb049f604003452d2dbcff4df3b34746df38807270c1c
Security Audit — socket — gitlab-automation