gitlab
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONCREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use
curlfor GitLab API interactions and provides shell commands for repository management, includinggit checkout,git add,git commit, andgit push. - [CREDENTIALS_UNSAFE]: The instructions suggest embedding the
GITLAB_TOKENenvironment variable directly into the git remote URL (e.g.,git remote set-url origin https://oauth2:${GITLAB_TOKEN}@gitlab.com/...). This practice causes the authentication token to be stored in plain text within the.git/configfile in the workspace. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: The skill interacts with GitLab repositories, branches, and API responses which can contain content (such as Merge Request descriptions or source code) controlled by external parties.
- Boundary markers: There are no instructions or delimiters provided to ensure the agent ignores or sanitizes malicious instructions embedded within the GitLab data it processes.
- Capability inventory: The skill allows for local file system modification (via git) and network requests (via curl).
- Sanitization: The skill lacks validation or sanitization logic for data retrieved from external GitLab resources before processing it.
Audit Metadata