{"data":{"skill":{"slug":"wshobson-gitlab-ci-patterns","name":"gitlab-ci-patterns","icon":"📦","repo":"https://github.com/wshobson/agents/tree/main/plugins/cicd-automation/skills/gitlab-ci-patterns","status":"approved","author":"wshobson","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"a7326c98-e929-42d3-9f42-93b8a51dd071","skill_id":"390f30d0-aeff-4965-a988-fe9ca8487127","version":6,"content_hash":"3da1b780333238b7b36ff76190fda1c7","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":"allowed","manual_install_policy":"allowed","summary":"Static command findings are mostly false positives because they appear inside GitLab CI YAML examples, not executable skill code. No prompt injection or malicious data exfiltration was found, but some examples recommend insecure deployment practices that require user review.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":39,"line_start":37},{"file":"SKILL.md","line_end":55,"line_start":52},{"file":"SKILL.md","line_end":68,"line_start":66},{"file":"SKILL.md","line_end":90,"line_start":85},{"file":"SKILL.md","line_end":105,"line_start":102},{"file":"SKILL.md","line_end":112,"line_start":111},{"file":"SKILL.md","line_end":124,"line_start":123},{"file":"SKILL.md","line_end":147,"line_start":145},{"file":"SKILL.md","line_end":155,"line_start":152},{"file":"SKILL.md","line_end":162,"line_start":160},{"file":"SKILL.md","line_end":173,"line_start":171},{"file":"SKILL.md","line_end":193,"line_start":192},{"file":"SKILL.md","line_end":235,"line_start":234}]},{"factor":"network","evidence":[{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":127,"line_start":127}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Insecure Kubernetes TLS Verification in Example","locations":[{"file":"SKILL.md","line_end":105,"line_start":102}],"confidence":0.91,"description":"The deployment template sets kubectl with --insecure-skip-tls-verify=true. Users who copy this pattern could accept spoofed Kubernetes API servers.","confidence_reasoning":"The insecure TLS flag is explicit in a deployment example. It is documentation rather than executable skill code, so the risk depends on user adoption."},{"title":"Docker Registry Password Passed on Command Line","locations":[{"file":"SKILL.md","line_end":86,"line_start":84}],"confidence":0.84,"description":"The Docker login example passes $CI_REGISTRY_PASSWORD with -p. This can expose secrets through process listings or logs in some CI environments.","confidence_reasoning":"The password flag is clearly shown in the sample. GitLab masking reduces some exposure, but safer stdin-based login should be recommended."},{"title":"Terraform Auto-Approve Deployment Pattern","locations":[{"file":"SKILL.md","line_end":176,"line_start":168}],"confidence":0.76,"description":"The Terraform apply job uses -auto-approve. A manual gate lowers risk, but copied pipelines could apply infrastructure changes without review.","confidence_reasoning":"The command is real and can be risky in infrastructure pipelines. Context includes a manual trigger, so this is a moderate configuration concern."}],"low_findings":[{"title":"Static Command Execution Matches Are CI Examples","locations":[{"file":"SKILL.md","line_end":74,"line_start":24},{"file":"SKILL.md","line_end":94,"line_start":78},{"file":"SKILL.md","line_end":131,"line_start":98},{"file":"SKILL.md","line_end":179,"line_start":135},{"file":"SKILL.md","line_end":195,"line_start":183},{"file":"SKILL.md","line_end":227,"line_start":199},{"file":"SKILL.md","line_end":247,"line_start":231}],"confidence":0.93,"description":"The external command findings occur inside fenced YAML examples. They are not executed by the skill and show ordinary CI job commands.","confidence_reasoning":"Every command match is within Markdown code fences for GitLab CI configuration. No repository script or runtime hook executes these commands."},{"title":"Hardcoded URLs Are Placeholder Environment URLs","locations":[{"file":"SKILL.md","line_end":73,"line_start":73},{"file":"SKILL.md","line_end":115,"line_start":115},{"file":"SKILL.md","line_end":127,"line_start":127}],"confidence":0.96,"description":"The hardcoded URLs use example.com hostnames for GitLab environment metadata. No outbound request logic or data exfiltration was found.","confidence_reasoning":"The URLs are reserved example domains used as deployment labels. They are not called by any executable skill code."},{"title":"Weak Cryptography Static Matches Are Lexical False Positives","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":270,"line_start":270}],"confidence":0.95,"description":"The weak cryptography detections map to descriptive text and related skill names. No cryptographic algorithm use was present.","confidence_reasoning":"The referenced lines contain GitLab CI wording and a related skill name. I found no MD5, SHA1, DES, RC4, or similar algorithm usage."}],"dangerous_patterns":[{"title":"Disabling TLS Verification","locations":[{"file":"SKILL.md","line_end":102,"line_start":102}],"confidence":0.91,"description":"The sample Kubernetes setup disables TLS certificate verification. This should be replaced with validated cluster certificate configuration.","confidence_reasoning":"The exact insecure flag is visible on the kubectl configuration line. The finding is limited to documentation guidance."},{"title":"Command-Line Secret Handling","locations":[{"file":"SKILL.md","line_end":85,"line_start":85}],"confidence":0.84,"description":"The Docker login example passes a password through a command option. A password-stdin pattern is safer for registry authentication.","confidence_reasoning":"The secret variable is used directly with the -p option. The sample is legitimate CI guidance but should be hardened."}],"files_scanned":1,"total_lines":272,"audit_model":"codex","audited_at":"2026-07-01T00:47:19.946+00:00","created_at":"2026-07-07T02:38:42.38797+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":5,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":"allowed","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}