GitLab Issue
Pass
Audited by Gen Agent Trust Hub on Mar 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from GitLab issue titles and descriptions.
- Ingestion points: Issue data retrieved via
gitlab-mcp(get_issue)andgitlab-mcp(list_issues)inSKILL.md. - Boundary markers: Absent. The skill does not utilize specific delimiters to isolate external data from instructions.
- Capability inventory: Write operations are available via
gitlab-mcp(create_issue)andgitlab-mcp(update_issue)inSKILL.md. - Sanitization: No explicit programmatic sanitization is defined, with the skill instead relying on LLM reasoning and the
Confirm with userdirective to prevent unauthorized actions.
Audit Metadata