Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

gitlab-cicd-hunter

النجوم١٥
التفرعات٧
آخر تحديث٢٨ يونيو ٢٠٢٦ في ١٦:٤٦

Audits GitLab repositories and CI/CD pipelines for exposed secrets in commit history / issues / MRs, insecure `.gitlab-ci.yml` patterns (hardcoded vars, privileged runners, Docker-socket mounts), webhook SSRF, reachable `.git/` directories, and `.bash_history` leaks on misconfigured hosts. Use when the target organization uses GitLab for SCM and/or CI/CD; after `web-recon-passive` surfaces repo references; or when the orchestrator identifies `gitlab.*` subdomains. Produces findings with CWE-798 / CWE-522 / CWE-918 mapping and pipeline-hardening remediation. Defensive testing only, READ-ONLY GitLab API calls.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

مستكشف الملفات
4 ملفات
SKILL.md
readonly