glab-cli
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a static command reference for the legitimate GitLab CLI tool (
glab). It does not contain executable scripts or automation instructions that could lead to unauthorized actions. - [CREDENTIALS_SAFE]: The file contains example authentication commands using placeholder strings (e.g.,
glpat-xxxxxxxxxxxx,s3cret). These are standard documentation practices and do not constitute credential exposure. - [COMMAND_EXECUTION]: The commands listed are intended for use by a developer with the
glabutility installed. They cover standard development workflows such as creating issues, managing merge requests, and checking pipeline status. - [DATA_EXPOSURE]: While the skill documents commands that interact with GitLab APIs, this behavior is expected for a tool designed for GitLab management. No evidence of data exfiltration or sensitive local file access was found.
Audit Metadata