Bundled agent skill uses :iid as a glab api placeholder, which is not expanded

Summary

The agent skill shipped with glab (glab skills install) uses :iid as if it were a glab api placeholder, for example:

glab api projects/:id/merge_requests/:iid -X PUT -f "assignee_id=1"
glab api projects/:id/merge_requests/:iid/discussions -X POST ...

glab api --help lists the placeholders as :branch, :fullpath, :group, :id, :namespace, :repo, :user, :username. :iid is not one and is sent literally.

Steps to reproduce

In a checkout with an open merge request:

glab api projects/:id/merge_requests/:iid

What happens

{"error":"merge_request_iid is invalid"}glab: HTTP 400

What should happen

Either the skill writes a real IID (merge_requests/<iid>, or $(glab mr view -F json | jq .iid)), or :iid becomes a placeholder resolved from the current branch's merge request.

An agent following the skill as written gets a 400 on every merge-request API call and typically falls back to guessing.

Version

glab 1.114.0 (4d7c6cda), skill installed with glab skills install --path <dir> --force on 2026-09-02.