Gitlab Cli Skills
by @vince-winkintel
Comprehensive GitLab CLI (glab) command reference and workflows for all GitLab operations. Use when working with merge requests, CI/CD pipelines, issues, rel...
clawhub install gitlab-cli-skillsπ About This Skill
name: gitlab-cli-skills description: Comprehensive GitLab CLI (glab) command reference and workflows for all GitLab operations via terminal. Use when user mentions GitLab CLI, glab commands, GitLab automation, MR/issue management via CLI, CI/CD pipeline commands, repo operations, authentication setup, or any GitLab terminal operations. Routes to specialized sub-skills for auth, CI, MRs, issues, releases, repos, and 30+ other glab commands. Triggers on glab, GitLab CLI, GitLab commands, GitLab terminal, GitLab automation. metadata: {"openclaw": {"requires": {"bins": ["glab"], "anyBins": ["cosign"]}, "install": [{"id": "brew", "kind": "brew", "formula": "glab", "bins": ["glab"], "label": "Install glab (brew)"}, {"id": "download", "kind": "download", "url": "https://gitlab.com/gitlab-org/cli/-/releases", "label": "Download glab binary"}]}} requirements: binaries: - glab binaries_optional: - cosign notes: | Requires GitLab authentication via 'glab auth login' (stores token in ~/.config/glab-cli/config.yml). Some features may access sensitive files: SSH keys (~/.ssh/id_rsa for DPoP), Docker config (~/.docker/config.json for registry auth). Review auth workflows and script contents before autonomous use. openclaw: requires: credentials: - name: GITLAB_TOKEN description: > GitLab personal access token with 'api' scope. Used by automation scripts (e.g. post-inline-comment.py) to post MR comments via the REST API. If not set, scripts fall back to reading the token from glab CLI config (~/.config/glab-cli/config.yml). required: false fallback: glab config (set via glab auth login) network: - description: Outbound HTTPS to your GitLab instance (default https://gitlab.com) scope: authenticated API calls only; HTTPS enforced; token never sent over HTTP write_access: - description: > Scripts in this skill can post comments, resolve threads, and approve merge requests on your behalf. Review scripts/post-inline-comment.py before use in automated or agentic contexts.
GitLab CLI Skills
Comprehensive GitLab CLI (glab) command reference and workflows.
Quick start
# First time setup
glab auth loginCommon operations
glab mr create --fill # Create MR from current branch
glab issue create # Create issue
glab ci view # View pipeline status
glab repo view --web # Open repo in browser
Multi-agent identity note
When you want different agents to appear as different GitLab users, give each agent its own GitLab bot/service account. Multiple personal access tokens on the same GitLab user still act as that same visible identity.
Use the Actor identity for actor-authored GitLab comments, replies, approvals, and other writes. Use an agent identity only when the GitLab action is explicitly that agent's own work product. Choose the intended visible actor before the first GitLab write.
Treat shell identity as sticky and unsafe by default. If another env file was sourced earlier in the same shell/session, glab may still write as that previously loaded identity unless you deliberately switch and verify first.
A practical pattern is one env file per actor, for example ~/.config/openclaw/env/gitlab-actor.env, ~/.config/openclaw/env/gitlab-reviewer.env, and ~/.config/openclaw/env/gitlab-release.env. Keep these env files outside version control, restrict their permissions (for example chmod 600), be mindful of backup exposure, and use least-privilege bot/service-account tokens. In a reused shell, clear stale GitLab auth vars first or start a fresh shell. If those files use plain KEY=value lines, load them with exported vars before running glab:
unset GITLAB_TOKEN GITLAB_ACCESS_TOKEN OAUTH_TOKEN GITLAB_HOST
set -a
source ~/.config/openclaw/env/gitlab-.env
set +a
Plain source updates the current shell but may not export variables to child processes such as glab. If the token/host vars are not exported, glab may silently fall back to shared stored auth from ~/.config/glab-cli/config.yml, which can make the wrong account appear to perform the action.
Required pre-flight before any GitLab write
Run this immediately before any GitLab write, including glab mr note, review replies/approvals, and any glab api POST/PATCH/PUT/DELETE call:
glab auth status --hostname "$GITLAB_HOST"
glab api --hostname "$GITLAB_HOST" user
This assumes the target actor env file set GITLAB_HOST for the exact GitLab instance you intend to modify. Do not write until both commands clearly show the intended visible actor on that host.
Wrong-identity remediation
If a comment or reply was posted under the wrong identity:
1. Stop posting.
2. Delete the mistaken comment or reply if cleanup is needed.
3. unset GITLAB_TOKEN GITLAB_ACCESS_TOKEN OAUTH_TOKEN GITLAB_HOST or start a fresh shell.
4. Source the correct env file with set -a; source ...; set +a.
5. Rerun glab auth status --hostname "$GITLAB_HOST" and glab api --hostname "$GITLAB_HOST" user.
6. Repost under the correct actor.
7. Verify the thread no longer shows the wrong visible author for the replacement message.
If the wrong-identity write changed state beyond a comment or reply, do not treat the comment cleanup steps as sufficient. Re-auth as above, then use the matching GitLab reversal for that write under the correct actor and host, such as unapproving an MR or sending the compensating glab api --hostname "$GITLAB_HOST" mutation for the exact resource that was changed.
Skill organization
This skill routes to specialized sub-skills by GitLab domain:
Core Workflows:
glab-mr - Merge requests: create, review, approve, mergeglab-issue - Issues: create, list, update, close, commentglab-ci - CI/CD: pipelines, jobs, logs, artifactsglab-repo - Repositories: clone, create, fork, manageProject Management:
glab-milestone - Release planning and milestone trackingglab-iteration - Sprint/iteration managementglab-label - Label management and organizationglab-release - Software releases and versioningAuthentication & Config:
glab-auth - Login, logout, Docker registry authglab-config - CLI configuration and defaultsglab-ssh-key - SSH key managementglab-gpg-key - GPG keys for commit signingglab-token - Personal and project access tokensglab-todo - Personal GitLab to-do triage and completionCI/CD Management:
glab-job - Individual job operationsglab-schedule - Scheduled pipelines and cron jobsglab-variable - CI/CD variables and secretsglab-securefile - Secure files for pipelinesglab-runner - Runner management: list, assign/unassign, inspect jobs/managers, pause/unpause, deleteglab-runner-controller - Runner controller, scope, and token management (EXPERIMENTAL, admin-only)Collaboration:
glab-user - User profiles and informationglab-snippet - Code snippets (GitLab gists)glab-incident - Incident managementglab-workitems - Work items: tasks, OKRs, key results, next-gen epicsAdvanced:
glab-api - Direct REST API callsglab-cluster - Kubernetes cluster integrationglab-deploy-key - Deploy keys for automationglab-quick-actions - GitLab slash command quick actions for batching state changesglab-stack - Stacked/dependent merge requestsglab-opentofu - Terraform/OpenTofu state managementUtilities:
glab-alias - Custom command aliasesglab-completion - Shell autocompletionglab-help - Command help and documentationglab-version - Version informationglab-check-update - Update checkerglab-changelog - Changelog generationglab-attestation - Software supply chain securityglab-duo - GitLab Duo AI assistantglab-mcp - Model Context Protocol server for AI assistant integration (EXPERIMENTAL)When to use glab vs web UI
Use glab when:
Use web UI when:
Common workflows
Daily development
# Start work on issue
glab issue view 123
git checkout -b 123-feature-nameCreate MR when ready
glab mr create --fill --draftMark ready for review
glab mr update --readyMerge after approval
glab mr merge --when-pipeline-succeeds --remove-source-branch
Code review
# List your review queue
glab mr list --reviewer=@me --state=openedReview an MR
glab mr checkout 456
glab mr diff
npm testApprove
glab mr approve 456
glab mr note 456 -m "LGTM! Nice work on the error handling."
CI/CD debugging
# Check pipeline status
glab ci statusView failed jobs
glab ci viewGet job logs
glab ci trace Retry failed job
glab ci retry
Decision Trees
"Should I create an MR or work on an issue first?"
Need to track work?
ββ Yes β Create issue first (glab issue create)
β Then: glab mr for
ββ No β Direct MR (glab mr create --fill)
Use glab issue create + glab mr for when:
Use glab mr create directly when:
"Which CI command should I use?"
What do you need?
ββ Overall pipeline status β glab ci status
ββ Visual pipeline view β glab ci view
ββ Specific job logs β glab ci trace
ββ Download build artifacts β glab ci artifact
ββ Validate config file β glab ci lint
ββ Trigger new run β glab ci run
ββ List all pipelines β glab ci list
Quick reference:
glab ci status, glab ci view, glab ci runglab ci trace, glab job retry, glab job viewglab ci artifact (by pipeline) or job artifacts via glab job"Clone or fork?"
What's your relationship to the repo?
ββ You have write access β glab repo clone group/project
ββ Contributing to someone else's project:
β ββ One-time contribution β glab repo fork + work + MR
β ββ Ongoing contributions β glab repo fork, then sync regularly
ββ Just reading/exploring β glab repo clone (or view --web)
Fork when:
Clone when:
"Project vs group labels?"
Where should the label live?
ββ Used across multiple projects β glab label create --group
ββ Specific to one project β glab label create (in project directory)
Group-level labels:
Project-level labels:
Related Skills
MR and Issue workflows:
glab-issue to create/track workglab-mr to create MR that closes issuescripts/create-mr-from-issue.sh automates thisCI/CD debugging:
glab-ci for pipeline-level operationsglab-job for individual job operationsscripts/ci-debug.sh for quick failure diagnosisRepository operations:
glab-repo for repository managementglab-auth for authentication setupscripts/sync-fork.sh for fork synchronizationConfiguration:
glab-auth for initial authenticationglab-config to set defaults and preferencesglab-alias for custom shortcutsπ‘ Examples
# First time setup
glab auth loginCommon operations
glab mr create --fill # Create MR from current branch
glab issue create # Create issue
glab ci view # View pipeline status
glab repo view --web # Open repo in browser