glab-securefile
Pass
Audited by Gen Agent Trust Hub on Jul 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documents the use of the
glabCLI tool for managing project secure files. It details shell commands for creating, downloading, and removing files from GitLab repositories as part of its primary functionality.\n- [DATA_EXFILTRATION]: The skill facilitates the transfer of sensitive files, such as.p12certificates and secure configuration files, between the local environment and GitLab. This is a standard operation for the documented tool and targets a well-known service (GitLab).\n- [PROMPT_INJECTION]: \n - Ingestion points: Data enters the environment from external GitLab repositories via the
glab securefile downloadcommand.\n - Boundary markers: No specific delimiters or safety instructions are provided to the agent for handling the contents of downloaded files.\n
- Capability inventory: The skill uses subprocess calls to execute the
glabCLI tool.\n - Sanitization: There is no evidence of sanitization performed on the content of the downloaded secure files before potential processing by the agent.
Audit Metadata