Peer Reviewer Assistant
Last updated: Aug 13, 2026
Fluid Attacks' PR/MR scanner is a comprehensive security analysis solution that automatically detects security issues by analyzing code changes in pull requests and merge requests (PR/MR) and provides immediate feedback to developers through automated discussions on GitLab, Azure DevOps, and GitHub platforms.
Security tests included
The assistant runs the following Fluid Attacks scanners on the code changes in each PR/MR:
- SAST, which detects vulnerabilities introduced in the application code.
- SCA, which detects vulnerabilities in the dependencies affected by the change.
- SS (Secret Scanning), which detects hardcoded secrets and credentials introduced in the change. Available on GitLab, GitHub and Azure DevOps.
The assistant does not currently run DAST, MAST, or CSPM analysis.
The Peer Reviewer Assistant is available only to groups on the Advanced plan.
Available only for cloud-hosted repositories. On-premises installations (GitLab, Azure DevOps, and GitHub Enterprise Server) are not supported.
Capabilities and use cases
Complete reference for Fluid Attacks MCP tools — analytics, vulnerability management, asset discovery, security scanning, DevSecOps, and knowledge base capabilities.
GitLab Peer Reviewer Assistant
Set up the Fluid Attacks Peer Reviewer Assistant for GitLab to get automated vulnerability scanning and comments on merge requests.