ns-gitlab-board-sync
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill integrates with an external service (GitLab) through a defined MCP (Model Context Protocol) interface (
mcp-gitlab-usage). All operations (label updates, status changes, time tracking) are performed on existing issues within the user's project context. - [SAFE]: Configuration is handled via a local template (
gitlab-sync-config.template.md) which correctly suggests using numeric IDs and labels rather than hardcoding sensitive credentials. It follows best practices by recommending the use of a.envor configuration file for environment-specific settings. - [SAFE]: The skill explicitly avoids creating new issues or performing destructive actions without context, and includes safeguards against overwriting existing estimates in GitLab.
- [TRUSTED_VENDOR]: The vendor 'nextstage-brasil' and its associated naming patterns in the metadata and instructions are recognized as legitimate resource references for this developer's suite of tools and do not represent a security risk.
Audit Metadata