gitlab-rn-web-before-after

Warn

Audited by Socket on Mar 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

Overall, the skill presents a coherent, legitimate tool for automated UI verification artifacts and MR documentation. It minimizes suspicious behavior by operating on local files and standard git/MR tooling, with optional remote interactions contingent on user-provided credentials. No malicious data exfiltration, credential harvesting, or autonomous real-world actions are evident. The primary risk lies in dependency on external tooling (glab) and environment-provided tokens for MR updates; ensure tokens are scoped and kept out of logs.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Mar 1, 2026, 02:14 PM
Package URL
pkg:socket/skills-sh/Ryan-Carloso%2Fskill-image-before-after%2Fgitlab-rn-web-before-after%2F@6ef73b3a6ce9aecf54e1321128b732fbfdbd1277