glab — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited glab (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Provides guidance for using glab, the official GitLab CLI, to perform GitLab operations from the terminal.
Invoke when the user needs to:
Verify glab installation before executing commands:
glab --versionIf not installed, inform the user and provide platform-specific installation guidance.
Most glab operations require authentication:
# Interactive authentication
glab auth login
# Check authentication status
glab auth status
# For self-hosted GitLab
glab auth login --hostname gitlab.example.org
# Using environment variables
export GITLAB_TOKEN=your-token
export GITLAB_HOST=gitlab.example.org # for self-hosted# 1. Ensure branch is pushed
git push -u origin feature-branch
# 2. Create MR
glab mr create --title "Add feature" --description "Implements X"
# With reviewers and labels
glab mr create --title "Fix bug" --reviewer=alice,bob --label="bug,urgent"# 1. List MRs awaiting your review
glab mr list --reviewer=@me
# 2. Checkout MR locally to test
glab mr checkout <mr-number>
# 3. After testing, approve
glab mr approve <mr-number>
# 4. Add review comments
glab mr note <mr-number> -m "Please update tests"# Create issue with labels
glab issue create --title "Bug in login" --label=bug
# Link MR to issue
glab mr create --title "Fix login" --description "Closes #<issue-number>"
# List your assigned issues
glab issue list --assignee=@me# Watch pipeline in progress
glab pipeline ci view
# Check pipeline status
glab ci status
# View logs if failed
glab ci trace
# Retry failed pipeline
glab ci retry
# Lint CI config before pushing
glab ci lintWhen not in a Git repository, specify the repository:
glab mr list -R owner/repo
glab issue list -R owner/repoSet hostname for all commands:
export GITLAB_HOST=gitlab.example.org
# or per-command
glab repo clone gitlab.example.org/owner/repoUse JSON output for parsing:
glab mr list --output=json | jq '.[] | .title'The glab api command provides direct GitLab API access:
# Basic API call
glab api projects/:id/merge_requests
# IMPORTANT: Pagination uses query parameters in URL, NOT flags
# ❌ WRONG: glab api --per-page=100 projects/:id/jobs
# ✓ CORRECT: glab api "projects/:id/jobs?per_page=100"
# Auto-fetch all pages
glab api --paginate "projects/:id/pipelines/123/jobs?per_page=100"
# POST with data
glab api --method POST projects/:id/issues --field title="Bug" --field description="Details"glab auth statusglab <command> --helpglab ci lintgit remote -vMerge Requests:
glab mr list --assignee=@me - Your assigned MRsglab mr list --reviewer=@me - MRs for you to reviewglab mr create - Create new MRglab mr checkout <number> - Test MR locallyglab mr approve <number> - Approve MRglab mr merge <number> - Merge approved MRIssues:
glab issue list - List all issuesglab issue create - Create new issueglab issue close <number> - Close issueCI/CD:
glab pipeline ci view - Watch pipelineglab ci status - Check statusglab ci lint - Validate .gitlab-ci.ymlglab ci retry - Retry failed pipelineRepository:
glab repo clone owner/repo - Clone repositoryglab repo view - View repo detailsglab repo fork - Fork repositoryFor detailed command documentation, refer to:
Load these references when:
"command not found: glab" - Install glab or verify PATH
"401 Unauthorized" - Run glab auth login
"404 Project Not Found" - Verify repository name and access permissions
"not a git repository" - Navigate to repo or use -R owner/repo flag
"source branch already has a merge request" - Use glab mr list to find existing MR
For detailed troubleshooting, load references/troubleshooting.md.
--web flag to open in browser--output=json for scripting and automation~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.