gitlab-automation

Warn

Audited by Socket on Apr 14, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s GitLab automation purpose broadly matches its capabilities, and the MCP endpoint appears to be official Composio/Rube infrastructure rather than an unrelated payload. However, the skill routes authentication and GitLab operations through a third-party intermediary, understates setup trust requirements ('no API keys needed'), and enables impactful write/admin actions. This is not confirmed malware, but it carries meaningful security and governance risk due to intermediary data flow and remote-service trust.

Confidence: 86%Severity: 64%
Audit Metadata
Analyzed At
Apr 14, 2026, 06:17 AM
Package URL
pkg:socket/skills-sh/sickn33%2Fantigravity-awesome-skills%2Fgitlab-automation%2F@391afc75e279f51c6298280cb600b8a8bd55ca50