glab-mcp

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exposes GitLab resources (issues, merge requests, project details, and pipeline logs) to the AI assistant. These sources constitute an ingestion point for untrusted data that may contain malicious instructions designed to override agent behavior.
  • Ingestion points: GitLab issue descriptions, merge request content, comments/notes, and CI/CD pipeline/job logs as described in references/commands.md.
  • Boundary markers: The provided documentation does not specify the use of delimiters or specific instructions to the model to ignore embedded commands within the retrieved GitLab data.
  • Capability inventory: The skill possesses significant capabilities including listing, creating, and updating issues and merge requests, as well as managing pipelines.
  • Sanitization: No explicit sanitization or filtering of the retrieved content is mentioned in the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:06 PM
Security Audit — agent-trust-hub — glab-mcp