gitlab
Warn
Audited by Socket on Apr 6, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Purpose and capabilities mostly align with GitLab administration, but the trust model is weak: the skill installs and relies on a third-party CLI, forwards GitLab credentials into it, and even documents disabling TLS verification for self-hosted use. This is better classified as suspicious/high-risk rather than outright malicious.
Confidence: 84%Severity: 82%
Audit Metadata