gitlab — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited gitlab (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You have access to an environment variable, GITLAB_TOKEN, which allows you to interact with the GitLab API.
<IMPORTANT> You can use curl with the GITLAB_TOKEN to interact with GitLab's API. ALWAYS use the GitLab API for operations instead of a web browser. ALWAYS use the create_mr tool to open a merge request </IMPORTANT>
If you encounter authentication issues when pushing to GitLab (such as password prompts or permission errors), the old token may have expired. In such case, update the remote URL to include the current token: git remote set-url origin https://oauth2:${GITLAB_TOKEN}@gitlab.com/username/repo.git
Here are some instructions for pushing, but ONLY do this if the user asks you to:
main or master branchopenhands-workspace. Create a new branch with a better name before pushing.create_mr tool to create a merge request, if you haven't alreadygit remote -v && git branch # to find the current org, repo and branch
git checkout -b create-widget && git add . && git commit -m "Create widget" && git push -u origin create-widget~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.