gitlab
Warn
Audited by Socket on Mar 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
Overall, the skill footprint is coherent with an automation helper for GitLab tasks but exhibits concerning credential-handling patterns (embedding tokens in git remote URLs and relying on curl with token). This is suspicious rather than clearly benign due to potential credential leakage vectors. Recommend refactoring to use header-based authentication, avoid embedding tokens in URLs, and implement secure secret handling and rotation checks. Overall risk: suspicious but not malicious.
Confidence: 75%Severity: 75%
Audit Metadata