gl

Warn

Audited by Socket on Apr 10, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it depends on a non-official third-party CLI and forwards GitLab tokens into it. The installer provenance is same-org and public, so this is not confirmed malware, but the remote installer and credential-forwarding pattern create medium security risk.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
Apr 10, 2026, 05:42 AM
Package URL
pkg:socket/skills-sh/x-cmd%2Fskill%2Fgl%2F@fff6e55a4b2b5c57a03e24bc85e8612b419cb6c3