create-mr
Warn
Audited by Socket on Mar 16, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s purpose is coherent, but it relies on a non-official ai-review CLI, reads a local credential file, and routes GitLab actions through third-party code that handles PAT-backed API operations. This is not confirmed malware, but the credential-forwarding and install-trust model make it higher risk than a direct GitLab integration.
Confidence: 83%Severity: 74%
Audit Metadata