gitlab-issue-to-mr
Audited by Socket on Sep 27, 2026
2 alerts found:
Anomalyx2SUSPICIOUS: the core GitLab/OpenHands data flows are coherent with the stated automation purpose and there is no evidence of malicious installers or credential exfiltration to unrelated domains. However, the skill intentionally lets issue-authored untrusted text drive an agent that can use GITLAB_TOKEN, optional additional secrets, forwarded MCP servers, and autonomous write actions (pushes, comments, merge requests), which makes the scope high-risk even though it is openly described.
This is intended to automate labeled GitLab issues by creating agent conversations, committing work, pushing branches, and opening merge requests. There is no clear evidence of deliberate malware, suspicious third-party destinations, or destructive behavior. The main security concern is granting an issue-driven agent access to GITLAB_TOKEN and relying on prompt instructions to constrain it; the broadly scoped git authorization header increases the impact of an unintended or malicious network operation. The provided text is also syntactically invalid, so the exact runnable implementation cannot be confirmed from this fragment.