ns-gitlab-board-sync

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill integrates with an external service (GitLab) through a defined MCP (Model Context Protocol) interface (mcp-gitlab-usage). All operations (label updates, status changes, time tracking) are performed on existing issues within the user's project context.
  • [SAFE]: Configuration is handled via a local template (gitlab-sync-config.template.md) which correctly suggests using numeric IDs and labels rather than hardcoding sensitive credentials. It follows best practices by recommending the use of a .env or configuration file for environment-specific settings.
  • [SAFE]: The skill explicitly avoids creating new issues or performing destructive actions without context, and includes safeguards against overwriting existing estimates in GitLab.
  • [TRUSTED_VENDOR]: The vendor 'nextstage-brasil' and its associated naming patterns in the metadata and instructions are recognized as legitimate resource references for this developer's suite of tools and do not represent a security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 10:20 PM
Security Audit — agent-trust-hub — ns-gitlab-board-sync