gitlab

Warn

Audited by Socket on Apr 6, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Purpose and capabilities mostly align with GitLab administration, but the trust model is weak: the skill installs and relies on a third-party CLI, forwards GitLab credentials into it, and even documents disabling TLS verification for self-hosted use. This is better classified as suspicious/high-risk rather than outright malicious.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
Apr 6, 2026, 03:29 AM
Package URL
pkg:socket/skills-sh/jorgemuza%2Forbit%2Fgitlab%2F@2f8be88ba9966abadb7354647c6f85dba4c8fda5