skills/openhands/extensions/gitlab/Gen Agent Trust Hub

gitlab

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use curl for GitLab API interactions and provides shell commands for repository management, including git checkout, git add, git commit, and git push.
  • [CREDENTIALS_UNSAFE]: The instructions suggest embedding the GITLAB_TOKEN environment variable directly into the git remote URL (e.g., git remote set-url origin https://oauth2:${GITLAB_TOKEN}@gitlab.com/...). This practice causes the authentication token to be stored in plain text within the .git/config file in the workspace.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: The skill interacts with GitLab repositories, branches, and API responses which can contain content (such as Merge Request descriptions or source code) controlled by external parties.
  • Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores or sanitizes malicious instructions embedded within the GitLab data it processes.
  • Capability inventory: The skill allows for local file system modification (via git) and network requests (via curl).
  • Sanitization: The skill lacks validation or sanitization logic for data retrieved from external GitLab resources before processing it.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:28 AM
Security Audit — agent-trust-hub — gitlab