gl
Pass
Audited by Gen Agent Trust Hub on Apr 10, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains standard instructional language for GitLab project management. No attempts to override safety filters or bypass core instructions were identified.
- [DATA_EXFILTRATION]: The skill mentions the requirement of a GitLab token for authentication. It does not contain patterns for hardcoded credentials, nor does it attempt to transmit sensitive data to external or untrusted domains.
- [REMOTE_CODE_EXECUTION]: No remote code execution vectors or suspicious script downloads from external sources were found. The commands shown use the vendor's own 'x-cmd' environment.
- [COMMAND_EXECUTION]: The commands provided (e.g., 'x gl cl', 'x gl snippet ls') are legitimate utilities for GitLab interaction and align with the skill's described purpose.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Interacts with GitLab project data such as snippets and repository content via the 'gl' tool (SKILL.md).
- Boundary markers: Not present in the instructional markdown.
- Capability inventory: Repository cloning and project management subcommands (SKILL.md).
- Sanitization: Not explicitly defined in the documentation files, but the surface is limited to standard CLI tool interaction with external APIs.
Audit Metadata