gitlab-mr-review

Warn

Audited by Socket on Apr 8, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The review behavior is broadly aligned with the stated purpose, and destructive repository changes are constrained. The main concern is install/data-flow trust: the skill directs users to a third-party GitLab MCP server and thereby encourages forwarding GitLab credentials to community code even though GitLab provides an official MCP endpoint. That makes the skill internally useful but not fully proportionate or trustworthy as written.

Confidence: 88%Severity: 72%
Audit Metadata
Analyzed At
Apr 8, 2026, 09:29 AM
Package URL
pkg:socket/skills-sh/ibuildingsnl%2Freusable-ai-prompts%2Fgitlab-mr-review%2F@c9170d83d240863fa68c12cb459f9cbe05520506