gitlab-issue-to-mr

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script uses subprocess.run to execute git commands for cloning, committing, and pushing. It employs safe practices by passing arguments as a list and using environment variables for credentials to prevent exposure in process lists.
  • [INDIRECT_PROMPT_INJECTION]: The automation is susceptible to indirect prompt injection because the agent ingests issue descriptions and discussion notes from GitLab. The skill mitigates this by providing a clear 'Required workflow' and explicit warnings to the agent. 1. Ingestion points: scripts/main.py fetches issue data and discussions via the GitLab API. 2. Boundary markers: The agent prompt in _build_implementation_prompt includes a specific 'untrusted input' warning section. 3. Capability inventory: Terminal access, file system writes (within the clone), and network access to GitLab and the OpenHands API. 4. Sanitization: The script redacts tokens from its own logs and error messages using the _redact helper.
  • [SAFE]: The GITLAB_TOKEN is managed securely via temporary environment-based configuration headers, ensuring the token is not stored in the repository's .git/config or visible in process monitoring tools. Additionally, file system operations include path validation to prevent traversal attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 03:37 PM
Security Audit — agent-trust-hub — gitlab-issue-to-mr