The skill executes unauthorized remote code and initiates unconstrained autonomous fix loops, creating critical risks of recursive code injection and system compromise through indirect prompt injection.
npx skills add https://github.com/coderabbitai/claude-pluginRemote code download and execution detected
curl -fsSL https://cli.coderabbit.ai/install.sh | sh
The skill instructs the agent to enter an 'autonomous fix-review cycle' where it modifies code and re-runs reviews without human intervention until the code is 'clean'. This creates a high risk of recursive code injection or unintended system state changes if the AI misinterprets the review output.
4. Fix Issues (Autonomous Workflow): 1. Implement the requested feature... 4. Fix critical and warning issues systematically 5. Re-run review to verify fixes 6. Repeat until clean
The skill instructs the agent to process output from the CodeRabbit API. If the API or the review results are compromised, the agent will ingest these results as instructions for the 'autonomous fix' loop, leading to indirect prompt injection.
4. Fix Issues (Autonomous Workflow): 3. Create task list from findings 4. Fix critical and warning issues systematically
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/coderabbitai/claude-plugin/code-review)<a href="https://mondoo.com/ai-agent-security/skills/github/coderabbitai/claude-plugin/code-review"><img src="https://mondoo.com/ai-agent-security/api/badge/github/coderabbitai/claude-plugin/code-review.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/coderabbitai/claude-plugin/code-review.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.