create-mr

Warn

Audited by Socket on Mar 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s purpose is coherent, but it relies on a non-official ai-review CLI, reads a local credential file, and routes GitLab actions through third-party code that handles PAT-backed API operations. This is not confirmed malware, but the credential-forwarding and install-trust model make it higher risk than a direct GitLab integration.

Confidence: 83%Severity: 74%
Audit Metadata
Analyzed At
Mar 16, 2026, 07:53 PM
Package URL
pkg:socket/skills-sh/zawlinnnaing%2Fai-review-cli%2Fcreate-mr%2F@91abacbd22716637a7e1c0619c2765f7cf5504ca