Back to skill

Security audit

Gitlab Skills

Security checks for vulnerabilities and agentic risk

Overview

This GitLab skill is mostly coherent, but it can perform high-impact repository writes without an enforceable confirmation gate.

Review this before installing if the agent will have a GitLab token with write permissions. Prefer project-scoped or read-only tokens where possible, keep GitLab protected branches and approval rules enabled, and require explicit human confirmation before creating issues/MRs, merging, or triggering pipelines. This does not look malicious, but the write authority is broad enough to merit Review.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/gitlab_cli.py:141
Finding

GitLab write operations bypass the documented user-confirmation gate

Content
View full analysis

Vulnerability Details

File Location: scripts/gitlab_cli.py:141-186, 220-244; related confirmation requirement in SKILL.md:74-75
Vulnerability Type: Missing authorization confirmation for state-changing operations
Risk Level: Medium

Vulnerable Code

python
def cmd_create_issue(cfg, args):
    body = {"title": args.title, "description": args.description}
    if args.labels:
        body["labels"] = args.labels
    i = request(cfg, "POST", f"/projects/{pid(args.project)}/issues",
                data=json.dumps(body))
    out({"iid": i["iid"], "title": i["title"], "url": i["web_url"]})


def cmd_create_mr(cfg, args):
    body = {"source_branch": args.source, "target_branch": args.target,
            "title": args.title, "description": args.description}
    m = request(cfg, "POST", f"/projects/{pid(args.project)}/merge_requests",
                data=json.dumps(body))
    out({"iid": m["iid"], "title": m["title"], "url": m["web_url"]})


def cmd_merge_mr(cfg, args):
    m = request(cfg, "PUT",
                f"/projects/{pid(args.project)}/merge_requests/{args.iid}/merge")
    out({"iid": m["iid"], "state": m["state"], "merged_by":
         (m.get("merged_by") or {}).get("username")})


def cmd_trigger_pipeline(cfg, args):
    body = {"ref": args.ref}
    p = request(cfg, "POST", f"/projects/{pid(args.project)}/pipeline",
                data=json.dumps(body))
    out({"id": p["id"], "status": p["status"], "ref": p["ref"],
         "url": p["web_url"]})

The argument parser exposes these handlers directly:

python
s = sub.add_parser("create-issue", help="create an issue")
s.add_argument("project")
s.add_argument("--title", required=True)
s.add_argument("--description", default="")
s.add_argument("--labels", default="")
s.set_defaults(func=cmd_create_issue)

s = sub.add_parser("create-mr", help="create a merge request")
s.add_argument("project")
s.add_argument("--source", required=True)
s.add_argument("--target", required=True)
s.a
...[truncated 2675 chars]
Remediation
View remediation

Remediation Suggestions

  1. Add a mandatory confirmation mechanism to every state-changing subcommand.
  2. Require the confirmation to identify the resolved operation and target, rather than accepting a generic Boolean where practical.
  3. Default write commands to dry-run mode and print the project, branch or ref, merge-request IID, and intended API operation.
  4. Reject non-interactive writes unless an explicit approval parameter is supplied after user review.
  5. For merge and pipeline operations, resolve and display relevant GitLab metadata before approval, including the project path, source and target branches, pipeline ref, and protected status where available.
  6. Keep server-side GitLab approval, protected-branch, and pipeline policies enabled as defense in depth.

A minimal CLI control could require a flag such as:

text
--confirm-project group/project --confirm-operation merge-mr

The handler should validate those values against the parsed and resolved target before issuing any authenticated write request.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (14)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 30)May include surrounding context.

export GITLAB_TOKEN="" # 需要 api 权限

text

Token 创建位置:User Settings → Access Tokens(勾选 `api`)。

## 运行方式

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/USAGE.md (reported line 19)May include surrounding context.

md
---

## 二、获取访问令牌(Access Token)

1. 登录 GitLab → 右上角头像 → **Preferences / Settings**。
2. 左侧 **Access Tokens**(个人令牌)。也可用项目级 / 群组级令牌。

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/USAGE.md (reported line 22)May include surrounding context.

md
## 二、获取访问令牌(Access Token)

1. 登录 GitLab → 右上角头像 → **Preferences / Settings**。
2. 左侧 **Access Tokens**(个人令牌)。也可用项目级 / 群组级令牌。
3. 勾选 **api** 作用域 → 创建并复制 token(只显示一次)。

---

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/gitlab_cli.py (reported line 7)May include surrounding context.

python
Connection is read from environment variables (or a JSON config file):

    GITLAB_URL    e.g. https://gitlab.com  (or self-hosted base URL)
    GITLAB_TOKEN  personal/project/group access token (scope: api)

Or put {"url": "...", "token": "..."} in ~/.devops-skills/gitlab.json.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 9)May include surrounding context.

md
## English

Manage GitLab projects, issues, merge requests, and CI/CD pipelines through the
GitLab REST API v4. The CLI supports project discovery, controlled write
operations, MR creation and merge, pipeline inspection, and pipeline triggers.

### Compatibility

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares no explicit tool scope or permission boundary even though it is designed to use environment variables and make network requests to GitLab APIs. In an agent setting, missing scope metadata can cause over-broad invocation and unclear authorization expectations, increasing the chance of unintended access to tokens or outbound calls.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: gitlab-skills
description: Manage GitLab projects from the command line — list/inspect projects, list and create issues, list/create/merge merge requests, and list or trigger CI/CD pipelines. Use whenever the user wants to work with a GitLab repo, file an issue, open or merge an MR, or kick off / check a pipeline on GitLab.com or a self-hosted GitLab. 中文触发场景:查 GitLab 项目、建 issue、开/合并 MR、查流水线、触发流水线、看流水线是否通过。
---

# GitLab 技能(命令行实操)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The activation text is very broad ('use whenever the user wants to work with a GitLab repo') and covers many sensitive actions, including write operations. Overly broad routing can cause the agent to invoke this skill in contexts where the user did not clearly intend authenticated GitLab API access or state-changing operations.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill enables implicit invocation without any trigger constraints, so the agent may auto-select it based on broad GitLab-related context rather than an explicit user request. Because this skill can inspect projects and perform state-changing actions such as creating issues, opening/merging merge requests, and triggering pipelines, unintended invocation could cause unauthorized or surprising operations against GitLab resources.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
80% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · references/USAGE.md (reported line 45)May include surrounding context.

}

text

> `chmod 600 ~/.devops-skills/gitlab.json`,不要把 token 提交到仓库。

---

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation demonstrates state-changing operations like merging MRs and triggering pipelines but does not mention confirmation, authorization checks, or risk warnings. In a skill intended for autonomous or semi-autonomous assistant use, this omission can lead to unintended repository changes, CI/CD executions, or production-affecting workflows.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The natural-language trigger examples are broad and action-oriented, which can cause the skill to be invoked for sensitive GitLab operations without sufficiently clear boundaries. In this context, the skill can create merge requests, merge code, and trigger pipelines, so ambiguous invocation guidance increases the chance of unintended state-changing actions.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

全文内容均以中文编写,包括标题、操作说明和自然语言触发示例,但没有说明该技能仅面向中文用户,或提供其他语言选项。按照语言/locale 策略,若技能实际上要求特定语言,应有明确的用户选择或合理约束说明。

Content

No source excerpt is available for this finding.

Unverifiable Dependency: requests has 16 known advisory(ies) (CVE-2014-1830 (Exposure of Sensitive Information to an Unauthorized Actor in Requests); CVE-2024-47081 (Requests vulnerable to .netrc credentials leak via malicious URLs); CVE-2024-35195 (Requests `Session` object does not verify requests after making first request wi) +13 more), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
95% confidence
Finding

The dependency specifier requests>=2.25,<3 allows installation of many versions, including releases with known security advisories, and does not guarantee a patched version will be used. In a GitLab automation skill that likely handles API tokens, repository metadata, and possibly self-hosted endpoints, a vulnerable requests version could increase the risk of credential leakage, TLS/redirect handling issues, or other client-side request vulnerabilities.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.