glab-securefile

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documents the use of the glab CLI tool for managing project secure files. It details shell commands for creating, downloading, and removing files from GitLab repositories as part of its primary functionality.\n- [DATA_EXFILTRATION]: The skill facilitates the transfer of sensitive files, such as .p12 certificates and secure configuration files, between the local environment and GitLab. This is a standard operation for the documented tool and targets a well-known service (GitLab).\n- [PROMPT_INJECTION]: \n
  • Ingestion points: Data enters the environment from external GitLab repositories via the glab securefile download command.\n
  • Boundary markers: No specific delimiters or safety instructions are provided to the agent for handling the contents of downloaded files.\n
  • Capability inventory: The skill uses subprocess calls to execute the glab CLI tool.\n
  • Sanitization: There is no evidence of sanitization performed on the content of the downloaded secure files before potential processing by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 09:15 AM
Security Audit — agent-trust-hub — glab-securefile