harden-gitlab-ci
Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask variables, pin job image digests, and use `id_tokens`/OIDC instead of long-lived secrets. Use when adding or auditing a `.gitlab
Profil aset
Agent pemrograman dan pengembangan
Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.
Skenario
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Kecocokan Agent
Claude Code + CLI + Codex
Cocok untuk Codex, Claude Code, Cursor, CLI, atau Agent khusus.
Pasang
Siap
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
Pemeliharaan
Terkini
1 hari sejak push
Risiko
Perlu ditinjau
Dependency or permission surface needs review
Kualitas GitHub
14
58/100 Kualitas · 66/100 Kepercayaan
Tag cakupan
Catatan ulasan
Dependency or permission surface needs review · Permission surface may require sandboxing
Kartu adopsi Agent
Kepercayaan, audit, dan kesiapan pemasangan dalam sekali lihat
Skor ini menggabungkan metadata repositori publik, sinyal ulasan OpenAgentSkill, kebaruan pemeliharaan, dan kesiapan pemasangan. Ini adalah sinyal shortlist, bukan pengganti peninjauan manusia.
Kualitas
MenjanjikanUseful candidate, but compare it with alternatives before adopting.
Kepercayaan
Do not auto-installTrust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Audit
Perlu ditinjauTinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Trust Score OpenAgentSkill v5
Tinjauan manusia sebelum pemasangan
Choose a stronger alternative or inspect the source manually before any install attempt.
Star
14 star GitHub
Aktivitas repositori
14 star dan 0 fork
Pemeliharaan
1 hari sejak push
Lisensi
MIT
Pasang
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
Keamanan pemasangan
Jalur pemasangan paket atau runtime standar
Cakupan izin
secrets or environment access, shell or command execution
Hasil Agent
Belum ada data hasil Agent
Dokumentasi
Konteks README/SKILL.md kuat
Ringkasan risiko
Tinjau sebelum produksi
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
Kesiapan pemasangan
Jalur pemasangan tersedia
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Lisensi dinyatakan
- Belum ada bukti hasil Agent-Proven
Metadata yang dapat dibaca Agent
Data keputusan yang dapat dibaca mesin untuk skill ini.
Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.
Tugas yang sesuai
- alur kerja GitHub automation
- Tim Claude Code
- builders willing to evaluate younger projects
- Inspect repository metadata
Agent yang sesuai
Keputusan pemasangan
- Perintah
- npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
- Kebijakan
- Blokir
- Tinjauan manusia
- Ya
Kepercayaan dan risiko
- Kepercayaan
- 58/100
- Audit
- 72/100
- Tingkat risiko
- Perlu ditinjau
Lingkar hasil
- Endpoint
- /api/agent/outcome
- ID event
- resolve
- Hasil
- 5
Perintah pemasangan
npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ciJangan gunakan ketika
- Tim yang membutuhkan SLA dengan dukungan vendor
- production agents without a repository review
- Low GitHub adoption signal
- Petunjuk izin berisiko tinggi: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Keamanan Agent v2
28/100 · Hindari pemasangan otomatis
This skill should not be selected by an agent without explicit human security review.
Do not auto-install. Inspect the source, dependencies, and permission surface first.
Tinggi
Eksekusi shell atau perintah
Metadata skill merujuk terminal, CLI, shell, subprocess, atau alur kerja eksekusi perintah.
Sedang
Akses jaringan
Skill kemungkinan mengambil halaman jarak jauh, API, repositori, atau layanan eksternal.
Sedang
Akses sistem file
Skill dapat membaca atau menulis file proyek, dokumen, artefak yang dihasilkan, atau status workspace lokal.
Tinggi
Secrets or environment access
Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.
- Petunjuk izin berisiko tinggi: Shell or command execution, Secrets or environment access
- Dependency or permission surface needs review
Target pemasangan
Pasang skill ini di alur Agent Anda
Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.
OpenAgentSkill CLI
Resolve policy, run the source installer safely, and report a verified install receipt.
$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install jrjsmrtn-harden-gitlab-ciRencana resolusi Agent
Biarkan Agent memverifikasi kecocokan sebelum memasang.
API Resolve mengembalikan skill utama, alternatif, kebijakan keamanan, catatan audit, target pemasangan, dan prompt siap pakai.
Buka JSON
/api/agent/resolve?task=Use%20harden-gitlab-ci%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Teks Resolve
/api/agent/resolve?task=Use%20harden-gitlab-ci%20for%20an%20agent%20workflow&agent=codex&max_risk=medium&format=text
Serah-terima pemasangan
/api/skills/jrjsmrtn-harden-gitlab-ci/install
Agent harus memeriksa
- Task fit and alternatives from Resolve API.
- Audit score, trust score, and safety policy warnings.
- Install target compatibility for Codex, Claude Code, Cursor, or CLI.
Salin prompt
Task: Use harden-gitlab-ci in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20harden-gitlab-ci%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/jrjsmrtn-harden-gitlab-ci/install
Install command: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.Serah-terima Agent
Berikan jalur pemasangan kepada Agent, bukan direktori lain.
Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.
Serah-terima pemasangan
/api/skills/jrjsmrtn-harden-gitlab-ci/install
Format teks LLM
/api/skills/jrjsmrtn-harden-gitlab-ci/install?format=text
Cari alternatif
/api/skills/search?q=harden-gitlab-ci&limit=3
Prompt Agent
Use harden-gitlab-ci for this task. Review https://www.openagentskill.com/api/skills/jrjsmrtn-harden-gitlab-ci/install, then install with: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ciMetadata Registry
Profil yang dapat dibaca Agent untuk pemilihan skill otomatis.
API Registry menyediakan sinyal keputusan, kepercayaan, audit, use case, dan pemasangan tanpa mengikis UI.
Manifest
/api/registry/manifest/jrjsmrtn-harden-gitlab-ci
Teks LLM
/api/registry/manifest/jrjsmrtn-harden-gitlab-ci?format=text
Alias pemasangan
/api/registry/install/jrjsmrtn-harden-gitlab-ci
Rekomendasikan
/api/registry/recommend?task=Use%20harden-gitlab-ci%20in%20an%20agent%20workflow&limit=3
Kecocokan Agent
GitHub automation
Platform
Claude Code
Laporan audit
Perlu ditinjau · 72/100
Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.
Panel keputusan Agent
Fallback candidate for GitHub automation
Prototype with this skill first; keep a fallback candidate ready.
Peran di stack
Kandidat cadangan
Kecocokan utama
GitHub automation
Label kepercayaan
Buat prototipe dulu
Jalur pemasangan
Perintah siap
Gunakan saat
- alur kerja GitHub automation
- Tim Claude Code
- builders willing to evaluate younger projects
Bukti
- recent repository activity
- install command or GitHub repo available
- profil kualitas 58/100
- 8 event interaksi OpenAgentSkill
tinjau dulu
- Low GitHub adoption signal
Jalur implementasi
- 1Pasang di Agent sandbox dan jalankan satu tugas GitHub automation dari awal hingga akhir.
- 2Compare output quality, latency, and failure behavior against at least one alternative.
- 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.
Profil kepercayaan
Do not auto-install
Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.
Adopsi GitHub
Perbaiki14 star GitHub
Aktivitas star/fork
Perbaiki14 star dan 0 fork; aktivitas issue tidak tersedia dalam metadata saat ini
Pemeliharaan terbaru
Lulus1 hari sejak push
Kejelasan lisensi
LulusMIT
Sinyal positif
- Tinjauan AI disetujui
- Jalur pemasangan tersedia
- Bukti repositori tersedia
- Repositori yang baru dipelihara
- Perintah pemasangan tidak memiliki pola berisiko tinggi yang jelas
- Loop hasil siap tetapi membutuhkan eksekusi Agent nyata pertama
Tinjau sebelum memasang
- Low GitHub adoption signal
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- GitHub adoption: 14 GitHub stars
- Stars/forks activity: 14 stars, 0 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
- Belum ada laporan hasil Agent nyata
- Tinjauan manusia diperlukan sebelum pemasangan tanpa pengawasan
Tindakan yang disarankan
Choose a stronger alternative or inspect the source manually before any install attempt.
Profil kualitas
Menjanjikan kandidat untuk alur kerja Agent
Useful candidate, but compare it with alternatives before adopting.
Kecocokan alur kerja
Gunakan skill ini pada skenario berikut
Manage repositories
GitHub automation
I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.
Build and ship code
Coding agents
I need a coding agent that can understand a repository, edit code, and review pull requests.
Operate web apps
Browser automation
I need my agent to control a browser, fill forms, and verify web app workflows.
Kecocokan alur kerja
Tambahkan ke alur kerja lengkap
Inspect, patch, and verify code
Coding review agent
A workflow for software agents that inspect repositories, review pull requests, generate tests, and turn findings into shippable patches.
Operate and verify web apps
Browser QA agent
A workflow for agents that navigate products, fill forms, take screenshots, and verify real user flows across web applications.
Design, build, test, and ship interfaces
Frontend and UI
A practical workflow for agents that turn product briefs or Figma designs into polished frontend code, review the result, test it in a browser, and prepare a safe deployment.
Daftar alternatif
Bandingkan sebelum memasang
Similar skills that may fit this task.
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
Infisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
Ringkasan
--- name: harden-gitlab-ci description: Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD components, scope the `CI_JOB_TOKEN` allowlist, protect and mask variables, pin job image digests, and use `id_tokens`/OIDC instead of long-lived secrets. Use when adding or auditing a `.gitlab-ci.yml`, before making a GitLab project public, when a supply-chain review flags CI gaps, or when standardizing pipeline hardening across GitLab projects (gitlab.com or self-hosted). GitLab-specific by design — for GitHub Actions use `harden-github-actions`; Forgejo/Gitea Actions are out of scope. metadata: author: "Georges Martin <jrjsmrtn@gmail.com>" version: "0.1.34" license: MIT ---
# Harden GitLab CI
Harden GitLab CI/CD pipelines against supply-chain attack: pin what runs, minimise what it can reach, and stop long-lived secrets from existing at all.
> **GitLab-specific by design.** Like `harden-github-actions`, this skill is deliberately bound to one > forge. The controls are properties of the GitLab CI execution model — `include:` resolution, the > `CI_JOB_TOKEN` allowlist, project/group variable scoping, `id_tokens` — not portable concepts in > GitLab syntax. It is a **sibling** of `harden-github-actions`, not a translation of it: the two > forges differ in what the risks *are*, not merely in how they are spelled.
## When to Use
- When adding a `.gitlab-ci.yml` to a project (after `setup-git-hooks`) - When auditing an existing pipeline before making a GitLab project public - When a supply-chain review (or the `supply-chain` skill) flags CI hardening gaps - When standardising pipeline hardening across GitLab projects
**Not for:** GitHub Actions (use `harden-github-actions`) or Forgejo/Gitea Actions. The controls do not carry over — say so rather than approximating.
## Required Inputs
1. **Repository** — a GitLab project (auto-detected from git remotes). **Self-hosted GitLab is a first-class target**, not an exception: authenticate once and every control below is identical. 2. **Project visibility** — public/internal or private. Phases 3 and 4 branch on it: public and internal projects expose pipeline artifacts to unauthenticated users, and fork merge requests are the main variable-exfiltration route. 3. **Scope** — what to run: - `audit` — report findings against the checklist below; **no writes** (default) - `fix` — apply the mechanical fixes (pin includes/components/images), leave judgment calls to the maintainer - `full` — `audit`, then `fix` after confirmation
## The GitLab Threat Model — What Actually Differs
Where the risk sits differs from GitHub Actions; the controls are not one-for-one equivalents:
| Concern | GitHub Actions | GitLab CI | |---|---|---| | Third-party code execution | `uses: actions/x@ref` from the Marketplace | **`include:` + CI/CD Catalog components** — same class of risk, different keyword | | Ambient credential | `GITHUB_TOKEN` with repo-wide default scopes | **`CI_JOB_TOKEN`** — defaults to *own project only*; risk is a widened allowlist | | Secret exfiltration surface | workflow can read all repo secrets | **variable scoping** — protected/masked/environment-scoped, plus fork-MR exposure | | Provenance / keyless auth | OIDC via `id-token: write` | **`id_tokens:` with an `aud` claim** | | Runner trust | GitHub-hosted vs self-hosted | **shared vs group/project runners**, `privileged` Docker, `shell` executor |
> **GitLab has a marketplace-shaped supply chain**: the **CI/CD Catalog** of components. Assuming > otherwise — that only GitHub has this problem — skips the pinning discipline entirely. GitLab's > own docs (*CI/CD components → Best practices*) say to "Pin CI/CD components to a specific commit > SHA (preferred) or release version tag to ensure the integrity of the component used in a > pipeline."
## Workflow
### Phase 1: Detect Context
1. Confirm the forge is GitLab and the CLI is authenticated: ```bash git remote -v glab auth status # self-hosted: glab auth login --hostname gitlab.internal.example ``` If the remote is GitHub or Forgejo, **stop** and point at the right sibling skill. 2. Locate the pipeline config. `glab ci lint` **defaults to `.gitlab-ci.yml` in the current directory**, but a project may relocate it (Settings → CI/CD → General pipelines → CI/CD configuration file). If it is relocated, `cd` to its directory or pass its path/URL — a bare lint would silently validate the wrong file, or nothing. 3. Validate it parses before changing anything: ```bash glab ci lint # or: glab ci lint <path-or-url> ``` 4. Inventory the third-party surface — run these and triage every hit (`CONFIG` = the config path):
```bash # Components/includes on a moving target: ~latest, a partial semver, or a branch grep -nE '@(~latest|[0-9]+(\.[0-9]+)?$|main|master)' "$CONFIG"
# include: project blocks — then confirm each has a `ref:` pinned to a 40-char SHA. # A missing ref: is a finding: it silently defaults to the target project's HEAD. grep -nA3 'include:' "$CONFIG" | grep -E 'project:|ref:' grep -nE '^\s*ref:\s*(?![0-9a-f]{40}\s*$)' -P "$CONFIG" # ref: present but not a SHA
# Remote includes — no auth, no ref to pin; each one is a trust-boundary decision grep -nE '^\s*-?\s*remote:' "$CONFIG"
# Images/services not pinned by digest (covers `image:` and `- name:` service entries; # the negative lookahead is what keeps already-pinned `foo:1@sha256:…` from false-positiving) grep -nPE '^\s*-?\s*(image|name):\s*(?!.*@sha256:)' "$CONFIG"
# Deprecated JWTs (see Phase 5) and inline secrets grep -nE 'CI_JOB_JWT' "$CONFIG"
# Runner isolation escapes grep -nE 'privileged:\s*true|executor:\s*shell' "$CONFIG" .gitlab-runner/*.toml 2>/dev/null ```
Treat every hit as a finding to justify or fix — not as noise to skim.
### Phase 2: Pin the Third-Party Supply Chain
This is the highest-value control — the direct analogue of SHA-pinning actions.
**CI/CD components** (`include: component`) — pin to a **commit SHA**:
```yaml include: # BAD — a moving target; ~latest re-resolves on every run - component: $CI_SERVER_FQDN/my-org/security-components/secret-detection@~latest
# GOOD — immutable - component: $CI_SERVER_FQDN/my-org/security-components/secret-detection@e3262fdd0914fa823210cdb79a8c421e2cef79d8 ```
Version resolution precedence, and why `~latest` is unsafe: a **commit SHA** is exact; a **tag** (`1.0.0`) is mutable unless the project protects its tags — and if a tag and SHA share a name, the SHA wins; a **branch** is fully mutable; `~latest`/partial semver re-resolves to whatever the Catalog last published. Prefer SHA; accept a release tag only when the component project protects tags.
**`include: project`** — `ref:` accepts a branch, tag, **or commit SHA**. Pin it:
```yaml include: - project: 'my-group/ci-templates' ref: 787123b47f14b552955ca2786bc9542ae66fee5b # not `main` file: '/templates/build.yml' ```
`ref:` is optional and **defaults to the project's HEAD** — an unpinned `include: project` silently tracks someone else's default branch. Treat a missing `ref:` as a finding, not a style nit.
**`include: remote`** — a public URL fetched over HTTP(S) with **no authentication support**. It is the weakest link: whoever controls that URL controls your pipeline, and there is no ref to pin. Prefer `component` or `project`. If a remote include is unavoidable, use a URL that embeds an immutable revision (a raw file path containing a commit SHA, not `/raw/main/`), and treat the host as part of your trust boundary.
**`include: template`** and **`include: local`** are GitLab-shipped or in-repo — no pinning needed.
**Resolving a tag to a SHA** — for a component or template project:
```bash # .id is the full commit SHA; :sha accepts a branch or tag name glab api "projects/my-org%2Fsecurity-components/repository/commits/1.0.0" --jq '.id' ```
`:fullpath` also works in place of the URL-encoded path when acting on the current project. For a non-GitLab-hosted template, `git ls-remote <url> refs/tags/<tag>` resolves the same thing.
**Job images and services** — pin by digest, keeping the tag for readability:
```yaml # BAD — mutable image: python:3.13 services: - postgres:18 ```
```yaml # GOOD — immutable, still readable image: python:3.13@sha256:<digest> services: - name: postgres:18@sha256:<digest> ```
Resolve digests with `skopeo inspect docker://python:3.13 --format '{{.Digest}}'`. This mirrors `setup-container-security`'s base-image rule; the reasoning and the bump procedure are the same.
### Phase 3: Scope the Job Token
`CI_JOB_TOKEN` is minted per job, scoped to the triggering user's access level, masked in logs, and revoked when the job ends. **By default it reaches only its own project** — so the work here is mostly *keeping* it that way. But verify the default actually holds before auditing anything else:
- **First, confirm the allowlist is enforced at all.** Under **Settings → CI/CD → Job token permissions**, the project may be set to either *"This project and any groups and projects in the allowlist"* (restricted — the default) or **"All groups and projects"** (permissive). GitLab's warning is unambiguous: *"If you disable the CI/CD job token allowlist, jobs from any project can access your project with a job token… You should only disable this setting for testing or a similar reason."* A project in the permissive mode has **no allowlist to audit** — that is the worst case and the finding. Fix it before reviewing entries. (Self-managed admins can force the restricted mode instance-wide via *Enable and enforce job token allowlist for all projects*.) - Then audit the allowlist: **Settings → CI/CD → Job token permissions → CI/CD job token allowlist**. Every entry is a project that may authenticate *into* this one. Justify each; remove the rest. (Limit: 200 entries — an allowlist near that size is a finding in itself.) - Adding to the allowlist **grants no new permissions** — the user must already have access. It widens *reachability*, not authority. Do not treat allowlist membership as an access grant. - Prefer the **fine-grained permissions** setting (limiting the token to a specific set of REST endpoints) over all-or-nothing allowlisting. - **Public/internal projects**: unauthenticated users can fetch artifacts from public pipelines regardless of the allowlist. If artifacts are sensitive, set feature visibility to *Only project members*. - Review the authentication log periodically for unexpected cross-project token use.
### Phase 4: Variables and Secrets
- **Never put secrets in `.gitlab-ci.yml`.** It is readable by anyone with repo access; it holds non-sensitive configuration only. Secrets live in project/group settings or a secrets manager. - **Protected** = available only to pipelines on protected branches/tags. **Masked** = redacted as `[MASKED]` in job logs. They solve different problems — set both for real secrets: ```bash # Read the secret into a variable; never inline it or echo it read -rs SECRET_VALUE glab variable set DEPLOY_TOKEN "$SECRET_VALUE" --masked --protected glab variable list -F json --jq '.[] | select(.masked==false or .protected==false) | .key' ``` That second command is the audit: any secret-shaped key it prints is a finding. - **Masking has hard constraints** — the value must be a single line, no spaces, ≥ 8 characters, and (with expansion enabled) use only `_ : @ - + . ~ = /` beyond alphanumerics. A secret that cannot be masked is a secret that will eventually appear in a log; regenerate it in a maskable format rather than shipping it unmasked. - **Masking is not a security boundary.** GitLab's own docs (*CI/CD variables → Mask a CI/CD variable*) state it "is not a guaranteed way to prevent malicious users from accessing variable values" — it defeats accid
Detail teknis
- Versi
- 1.0.0
- Lisensi
- MIT
- Pembaruan terakhir
- 21 Agu 2026
- Diterbitkan
- 21 Agu 2026
Ringkasan keputusan
Kandidat cadangan
recent repository activity
Audit
Tinjauan pemasangan
Tinjauan pemasangan dan adopsi
- Keamanan
- 72/100
- Pemeliharaan
- 100/100
- Pasang
- 92/100
Bukti tervalidasi Agent
Bukti tervalidasi Agent
Laporan hasil setelah resolve, tinjau, pasang, dan satu eksekusi terbatas.
- Tingkat sukses
- —
- Kegagalan terbaru
- —
- Hasil
- 0
- Kualitas output
- —
- Gagal
- 0
- Tidak relevan
- 0
- Pemasangan
- 0
- Diblokir risiko
- 0
- Perlu penyiapan
- 0
- Produksi
- 0
Belum ada data hasil Agent. Eksekusi pertama dapat melaporkan keberhasilan, kebutuhan setup, blok risiko, kegagalan, atau tidak relevan melalui /api/agent/outcome.
Pasang
Tambahkan ke alur Agent
Gratis dan sumber terbuka. Tinjau laporan sebelum memasang pada Agent produksi.
Siklus pertumbuhan
Kit berbagi
Draf berbasis skenario untuk harden-gitlab-ci, siap untuk posting manual di X.
harden-gitlab-ci: Harden GitLab CI/CD pipelines for supply-chain security — SHA-pin `include:` and CI/CD compon... 14 stars https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci?ref=x
Balasan opsional dengan perintah pemasangan
Listing + install path for harden-gitlab-ci: https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci?ref=x Install: npx skills add jrjsmrtn/project-orchestration-skills --skill harden-gitlab-ci
Sumber listing
Diindeks Registry
Listing ini diindeks dari sumber publik dan belum ditandai resmi hingga klaim pemelihara disetujui.
- Kreator
- jrjsmrtn
- Diindeks oleh
- Indeks komunitas OpenAgentSkill
Atribusi menautkan ke repositori publik atau profil kreator. Kreator dapat mengklaim listing untuk memperbarui sinyal kepemilikan.
Klaim skill iniKlaim pemilik
Klaim listing skill ini
Listing Diindeks Registry ini dikaitkan dengan jrjsmrtn, tetapi belum ditandai resmi. Klaim untuk menambahkan sinyal pemilik terverifikasi dan membuat pembaruan peluncuran, pemasangan, serta audit berikutnya lebih tepercaya.
Kit backlink kreator
Tambahkan badge bukti ke README Anda
Tampilkan listing kanonis, sinyal kepercayaan dan audit saat ini, serta bukti Agent-Proven nyata di tempat pengembang mengevaluasi repositori.
[](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)
[](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)
[](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci/audit)
[](https://www.openagentskill.com/skills/jrjsmrtn-harden-gitlab-ci)Penulis
jrjsmrtn
@jrjsmrtn
Tag
Kecocokan platform
Sinyal kesehatan
- Star GitHub
- 14
- Skor kualitas
- 32/100
- Push GitHub terakhir
- 21 Agu 2026
- Petunjuk framework
- Tidak diketahui
- Tampilan OpenAgentSkill
- 8
- Salinan pemasangan
- 0
- Klik keluar
- 0
Sinyal komunitas
Bagikan apakah skill ini bermanfaat untuk alur kerja Agent Anda. Masukan gabungan meningkatkan peringkat dari waktu ke waktu.
Kepercayaan & keamanan
Do not auto-install
- Adopsi GitHub14 star GitHubPerbaiki
- Aktivitas star/fork14 star dan 0 fork; aktivitas issue tidak tersedia dalam metadata saat iniPerbaiki
- Pemeliharaan terbaru1 hari sejak pushLulus
- Kejelasan lisensiMITLulus
- Kelengkapan README/SKILL.mdMetadata memuat konteks penggunaan dan alur kerja yang cukupLulus
- Risiko dependensi/runtimecommand execution surface, credential or environment accessPerbaiki
Skill terkait
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16.3K StarMaigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
32.9K StarNuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29.2K StarInfisical
Infisical is the open-source platform for secrets, certificates, and privileged access management.
27.4K Star