Skip to main content
Jeden Skill in Manus ausführen
mit einem Klick

gitlab-cicd-hunter

Sterne15
Forks7
Aktualisiert28. Juni 2026 um 16:46

Audits GitLab repositories and CI/CD pipelines for exposed secrets in commit history / issues / MRs, insecure `.gitlab-ci.yml` patterns (hardcoded vars, privileged runners, Docker-socket mounts), webhook SSRF, reachable `.git/` directories, and `.bash_history` leaks on misconfigured hosts. Use when the target organization uses GitLab for SCM and/or CI/CD; after `web-recon-passive` surfaces repo references; or when the orchestrator identifies `gitlab.*` subdomains. Produces findings with CWE-798 / CWE-522 / CWE-918 mapping and pipeline-hardening remediation. Defensive testing only, READ-ONLY GitLab API calls.

Installation

Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.

Datei-Explorer
4 Dateien
SKILL.md
readonly