glab-repo

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the glab CLI and a bundled shell script scripts/sync-fork.sh to automate repository management tasks such as cloning, forking, and syncing. These are standard operations for a version control management tool.
  • [PROMPT_INJECTION]: The skill includes an attack surface for indirect prompt injection by processing external data from GitLab (repository names, descriptions, and member lists). This is a known risk for agents interacting with external platforms.
  • Ingestion points: SKILL.md (via glab repo search, glab repo view, glab repo list, and glab repo members list commands).
  • Boundary markers: None identified.
  • Capability inventory: File system access (clone/archive), network access (push/pull), and destructive actions (glab repo delete, glab repo transfer).
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 05:21 AM
Security Audit — agent-trust-hub — glab-repo