Files
vince-winkintel__gitlab-cli…/glab-job
Vince Lozada 732ab95906 security: address HIGH/MEDIUM findings from skills.sh audit (#35)
* security: address HIGH/MEDIUM findings from skills.sh audit

- Remove eval from mr-review-workflow.sh; add command allowlist
- Replace direct config file parsing with glab auth token in add-inline-comment.sh
- Add external content boundary markers to create-mr-from-issue.sh and ci-debug.sh
- Add private key upload warning to glab-ssh-key/SKILL.md
- Add prompt injection warnings to glab-api, glab-ci, glab-job SKILL.md files
- Add SECURITY.md with full security policy and guidance

Fixes #34

* chore: exclude SECURITY.md from zip export

---------

Co-authored-by: Steven (Bot) <steven@winkintel.com>
2026-03-04 19:41:38 -06:00
..