GitLab Agent
Operate assigned GitLab work with owner-verified project access and guarded MR delivery. Skill: GitLab Agent Owner: xrowgmbh Summary: Operate assigned GitLab work with owner-verified project access and guarded MR delivery. Tags: latest:1.108.1 Version history: v1.108.1 | 2026-10-08T22:08:54.725Z | auto - Removed the file skill-card.md. - No changes made to code or logic; documentation file only removed. - Existing functionality and skill behavior remain unchanged. v1.108.0 | 2026-10-08T20:08:23.897Z | au
Rank
62
Safety
84
Downloads
6.1k
Updated
Oct 9, 2026
Version
1.108.1
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 6.1K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 6.1K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.108.1release · observed Oct 8, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17aekq8k9ea9rzxqpwjjz8ea987ze4c:xrowgmbh-gitlab-agent- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-xrowgmbh-xrowgmbh-gitlab-agent/snapshot"
Documentation
CLAWHUB
157,505 characters of source documentation, loaded on request.
Extracted files
4 files captured from the source.
SKILL.md
---
name: gitlab-agent
description: "Operate assigned GitLab work with owner-verified project access and guarded MR delivery."
metadata: { "openclaw": { "requires": { "bins": ["glab", "jq"] }, "primaryEnv": "GITLAB_TOKEN" } }
---
# GitLab Agent Skill
Repeat and fullfill your `GitLab Agent` tasks.
* If you have questions or options what to do next, decide on your own.
* All actions do not require confirmation or approval.
* Do not use the internal `Workboard` or any other tools to manage your work, just use GitLab.
* Your Environment is isolated
* Write behavior is permitted, required and desired.
* You have the role of a [developer](https://docs.gitlab.com/user/permissions/#default-roles). You can not push to protected branches.
* Every write action is low risk and can be reverted, so do not worry about making mistakes.
* Perform all also external, irreversible actions (like clone/push/create MR) automatically without your explicit confirmation. Confirmation is granted by the owner when you were created.
## Goals
* All writable actions in GitLab should be done with the `glab` CLI. This includes creating and updating issues, merge requests, branches, comments, and more.
* Complete tasks successfully in GitLab.
* If you think work needs to be done, do it without asking.
## Security Gate
Skip the security gate for `owner`. Otherwise, the security gate is mandatory.
Before reading or working an existing issue, work item, or merge request beyond the minimum fields needed to identify its project and assignment:
1. Resolve the owner GitLab username from `GITLAB_AGENT_OWNER`, or from the active workspace `USER.md` field `GitLab Username` when the environment variable is unset.
2. Resolve the target project path from the object's GitLab URL.
3. Run `{baseDir}/scripts/check-project-access.py <project-path> <owner-username> <issue|merge_request> <iid>`.
4. Continue only when the script succeeds. The script removes `workflow::forbidden` after an allowed check.
5. On failure, do not analyze the object, clone the project, push, comment, retry CI, or otherwise work on it. The script replaces its existing `workflow::*` label with `workflow::forbidden`; stop work on that project object and report the failed gate locally.
6. Never add or remove `workflow::forbidden` directly; only the security-check script owns that label.
The check fails closed when the current GitLab user has no active project membership, membership data is incomplete, or the membership was not created by the configured owner.
## Assignment Gate
Before working an existing issue, work item, or merge request, check the current GitLab user and the assignees on that object.
* If the current GitLab user is not an assignee, do not work the ticket.
* If the ticket assigment origin was a gateway channel (like a human request, or a bot request). If you can`t assign it to yourself. If you can not assign it to yourself because you are not a team member, fork the project, create a new is_meta.json
{
"ownerId": "kn7frykp2tnj00b0czk5f4r505809an4",
"slug": "xrowgmbh-gitlab-agent",
"version": "1.108.1",
"publishedAt": 1791497334725
}references/documentation-style.md
# Write user documentation 1. Start with the reader's task and intended result. Put prerequisites before commands and expected results after them. Include one minimal working example the reader can follow from start to finish. 2. Verify commands, options, defaults, and limitations against the implementation. Preserve exact names in code formatting. Distinguish tested behavior from assumptions, and explain limitations beside the action they affect. 3. Edit for clarity. Use direct verbs, short sentences, normal word spacing, and one topic per paragraph. Replace vague claims such as "robust" or "seamless" with the specific behavior the reader needs to know. 4. Organize for scanning. Use sentence-case headings, numbered steps for ordered tasks, and tables for settings or comparisons. Link to detailed references instead of repeating them. Keep retry history, pipeline IDs, commit hashes, and agent bookkeeping in the MR or work log; user guides describe current behavior. 5. Read the rendered page as a user before committing. Check that prerequisites, commands, expected results, and links are easy to find. Remove repeated summaries, irrelevant implementation details, and decorative emphasis. Run the repository's existing documentation lint and build checks. ## Example Before: > The chart enables post-installation validation of service discoverability. After: > After installation, run `helm test openclaw -n openclaw` to check that cluster > DNS can resolve the Service.
skill-card.md
## Description: Operate assigned GitLab work with owner-verified project access and guarded MR delivery. This skill is ready for commercial/non-commercial use. ## Publisher: [xrowgmbh](https://clawhub.ai/user/xrowgmbh) ### License/Terms of Use: MIT-0 ## Use Case: Developers and engineering teams use this skill to work assigned GitLab issues and merge requests, check project access, deliver code changes, and manage review and pipeline workflows. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Unattended GitLab actions can modify project work and code without per-action approval. Mitigation: Use a tightly scoped GitLab account and write-capable token; restrict project membership to intended projects. Risk: Recurring runs can repeatedly claim incidents or alter merge requests, reviewers, labels, and pipelines. Mitigation: Review the recurring schedule before enabling it, and monitor GitLab activity. ## Reference(s): - [GitLab Agent release on ClawHub](https://clawhub.ai/xrowgmbh/skills/xrowgmbh-gitlab-agent) - [GitLab default project roles](https://docs.gitlab.com/user/permissions/#default-roles) - [Documentation style guide](references/documentation-style.md) - [Skill feedback project](https://gitlab.com/xrow-public/skills) ## Skill Output: **Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration guidance] **Output Format:** [Markdown with GitLab links and code blocks] **Output Parameters:** [1D] **Other Properties Related to Output:** [Can also update GitLab issues, merge requests, branches, labels, reviewers, and pipelines.] ## Skill Version(s): 1.108.1 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/xrowgmbh/skills/xrowgmbh-gitlab-agent",
"sourceUrl": "https://clawhub.ai/xrowgmbh/skills/xrowgmbh-gitlab-agent",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T03:31:08.444Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xrowgmbh-xrowgmbh-gitlab-agent/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xrowgmbh-xrowgmbh-gitlab-agent/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T03:31:08.444Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "6.1K downloads",
"href": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceUrl": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T03:31:08.444Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.108.1",
"href": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceUrl": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-08T22:08:54.725Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-xrowgmbh-xrowgmbh-gitlab-agent/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-xrowgmbh-xrowgmbh-gitlab-agent/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.108.1",
"description": "- Removed the file skill-card.md. - No changes made to code or logic; documentation file only removed. - Existing functionality and skill behavior remain unchanged.",
"href": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceUrl": "https://clawhub.ai/xrowgmbh/xrowgmbh-gitlab-agent",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-10-08T22:08:54.725Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
