glab-repo
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes the
glabCLI and a bundled shell scriptscripts/sync-fork.shto automate repository management tasks such as cloning, forking, and syncing. These are standard operations for a version control management tool. - [PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection by processing external data from GitLab (repository names, descriptions, and member lists). This is a known risk for agents interacting with external platforms.
- Ingestion points:
SKILL.md(viaglab repo search,glab repo view,glab repo list, andglab repo members listcommands). - Boundary markers: None identified.
- Capability inventory: File system access (clone/archive), network access (push/pull), and destructive actions (
glab repo delete,glab repo transfer). - Sanitization: None identified.
Audit Metadata