Back to skill

Security audit

GitLab Agent Self Improvement

Security checks across malware telemetry and agentic risk

Overview

The skill is framed as personal self-improvement but actually asks an agent with GitLab credentials to create, assign, and close merge requests in a live project.

Install only if you intend this skill to operate on the named GitLab project with a token capable of merge request actions. Use a minimally scoped token, review every proposed MR action before execution, and be especially careful with the instruction to close older merge requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (4)

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The skill is presented as personal self-improvement, but its actual behavior directs the agent to operate on a live GitLab project by creating and closing merge requests. This mismatch can mislead users and safety systems about the skill’s real capabilities and purpose, increasing the chance of unauthorized or unexpected repository modifications.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
The skill requests GitLab CLI access and a GitLab token even though its stated purpose is self-improvement, which is not a capability-justified need. Granting repository write-capable tooling under an unrelated label expands attack surface and could enable unintended project changes if the skill is invoked casually or automatically.

Vague Triggers

Medium
Confidence
91% confidence
Finding
The activation instructions are broad and subjective, such as telling the agent to think about improvements and stop only if changes seem cosmetic, without clear triggers or boundaries. This can cause the agent to initiate repository-affecting actions in ambiguous situations, making unintended modifications more likely.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The instructions explicitly tell the agent to create, assign, and close merge requests, all of which are repository-changing actions, but they provide no user-facing warning or confirmation step. In context, this is more dangerous because the skill combines write-capable GitLab access with autonomous instructions to alter project workflow state.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.