GitLab Issue

Pass

Audited by Gen Agent Trust Hub on Mar 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes untrusted data from GitLab issue titles and descriptions.
  • Ingestion points: Issue data retrieved via gitlab-mcp(get_issue) and gitlab-mcp(list_issues) in SKILL.md.
  • Boundary markers: Absent. The skill does not utilize specific delimiters to isolate external data from instructions.
  • Capability inventory: Write operations are available via gitlab-mcp(create_issue) and gitlab-mcp(update_issue) in SKILL.md.
  • Sanitization: No explicit programmatic sanitization is defined, with the skill instead relying on LLM reasoning and the Confirm with user directive to prevent unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 13, 2026, 08:06 AM