gitlab-issue-to-mr
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The script uses
subprocess.runto executegitcommands for cloning, committing, and pushing. It employs safe practices by passing arguments as a list and using environment variables for credentials to prevent exposure in process lists. - [INDIRECT_PROMPT_INJECTION]: The automation is susceptible to indirect prompt injection because the agent ingests issue descriptions and discussion notes from GitLab. The skill mitigates this by providing a clear 'Required workflow' and explicit warnings to the agent. 1. Ingestion points:
scripts/main.pyfetches issue data and discussions via the GitLab API. 2. Boundary markers: The agent prompt in_build_implementation_promptincludes a specific 'untrusted input' warning section. 3. Capability inventory: Terminal access, file system writes (within the clone), and network access to GitLab and the OpenHands API. 4. Sanitization: The script redacts tokens from its own logs and error messages using the_redacthelper. - [SAFE]: The
GITLAB_TOKENis managed securely via temporary environment-based configuration headers, ensuring the token is not stored in the repository's.git/configor visible in process monitoring tools. Additionally, file system operations include path validation to prevent traversal attacks.
Audit Metadata