cicd-aiops
Use this skill whenever the user needs to operate a self-managed GitLab or self-hosted Gitea CI/CD server — a one-shot overview, server version and token identity, projects with storage statistics, pipelines/runs with jobs and trace tails, the runner fleet, merge/pull requests, branches, protection rules and releases, artifact inventories, four flagship RCAs (pipeline failures, runner health & queue, artifact/storage bloat, stale work), and governed writes (retry/cancel a pipeline, pause/resume a runner, delete artifacts, update branch protection). Always use this skill for "GitLab", "Gitea", "pipeline failed", "CI is red", "job trace", "runner offline", "jobs stuck in queue", "artifact storage full", "stale merge requests", "stale branches", "protect the default branch", "retry the pipeline", "cancel the pipeline", "delete old artifacts" when the context is a self-managed GitLab or Gitea instance. Do NOT use when the target is something other than a GitLab/Gitea CI/CD server (a hypervisor, storage appliance, backup product, database, network gear, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Do NOT use for Kubernetes deploy state — use k8s-aiops. GitLab.com / Gitea Cloud SaaS accounts are out of scope: this tool targets self-managed instances. Governed CI/CD operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).
Rank
62
Safety
84
Downloads
1.6k
Updated
Oct 10, 2026
Version
0.10.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.6K downloads reported by the source. Last updated 10/10/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 10, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 10, 2026
- Adoption signal
- 1.6K downloadsadoption · observed Oct 10, 2026
- Latest release
- 0.10.3release · observed Sep 15, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:cicd-aiops- Install using `clawhub skill install s171xgnmqse0nqvgqvqnaq5f9183kyre:cicd-aiops` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/zw008/cicd-aiops before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-zw008-cicd-aiops/snapshot"
Documentation
CLAWHUB
149,448 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: cicd-aiops
slug: cicd-aiops
displayName: "CICD AIops"
summary: "Governed self-managed GitLab + Gitea CI/CD ops: pipelines, runners, artifacts, RCA. 28 tools."
license: MIT
homepage: https://github.com/AIops-tools/CICD-AIops
tags: [aiops, mcp, governance, cicd]
description: >
Use this skill whenever the user needs to operate a self-managed GitLab or self-hosted Gitea CI/CD server — a one-shot overview, server version and token identity, projects with storage statistics, pipelines/runs with jobs and trace tails, the runner fleet, merge/pull requests, branches, protection rules and releases, artifact inventories, four flagship RCAs (pipeline failures, runner health & queue, artifact/storage bloat, stale work), and governed writes (retry/cancel a pipeline, pause/resume a runner, delete artifacts, update branch protection).
Always use this skill for "GitLab", "Gitea", "pipeline failed", "CI is red", "job trace", "runner offline", "jobs stuck in queue", "artifact storage full", "stale merge requests", "stale branches", "protect the default branch", "retry the pipeline", "cancel the pipeline", "delete old artifacts" when the context is a self-managed GitLab or Gitea instance.
Do NOT use when the target is something other than a GitLab/Gitea CI/CD server (a hypervisor, storage appliance, backup product, database, network gear, or OT/industrial equipment) — route those to the appropriate other AIops-tools skill. Do NOT use for Kubernetes deploy state — use k8s-aiops. GitLab.com / Gitea Cloud SaaS accounts are out of scope: this tool targets self-managed instances.
Governed CI/CD operations with a built-in governance harness (audit, policy, token budget, undo, risk-tiers).
installer:
kind: uv
package: cicd-aiops
argument-hint: "[a project path, pipeline/runner id, or describe your CI/CD task]"
allowed-tools:
- Bash
metadata: {"openclaw":{"requires":{"anyBins":["cicd-aiops","uvx"]},"optional":{"env":["CICD_AIOPS_CONFIG","CICD_AIOPS_MASTER_PASSWORD"]},"homepage":"https://github.com/AIops-tools/CICD-AIops","emoji":"🔁","os":["macos","linux"]}}
compatibility: >
Standalone, self-governed CI/CD operations across self-managed GitLab (REST API v4 /api/v4/..., access token via PRIVATE-TOKEN header) and self-hosted Gitea (API v1 /api/v1/..., access token via "Authorization: token"). Each target in the config names its own platform, and a name-keyed platform registry selects the API shape, so the same tools work on both and one config can span a mixed estate; surfaces one platform lacks (e.g. runner administration on Gitea) raise a teaching error listing what is available. The governance harness (audit, policy, token/runaway budget, undo, risk-tiers) is bundled in the package — no external skill-family dependency.
All write operations are audited to a local SQLite DB under ~/.cicd-aiops/ (relocatable via CICD_AIOPS_HOME).
Credentials: the GitLab personal/project access token or Gitea access token is stored ENCRYPTED in ~/.cicd-aiops/secr_meta.json
{
"ownerId": "kn7b067awq2s97bn3d7p5qfhw5827pxc",
"slug": "cicd-aiops",
"version": "0.10.3",
"publishedAt": 1789451311953
}references/agent-guardrails.md
# Agent guardrails — running cicd-aiops with a smaller / local model
If you drive these tools with a local model (Llama, Qwen, Mistral … via Goose,
Ollama, LM Studio, or any OpenAI-compatible runtime), you will get noticeably
better results with a short system prompt. This page gives you one, and — more
importantly — tells you which guardrails you **no longer need to write**, because
the tool now enforces them itself.
The distinction matters. A guardrail in a prompt is a request. A guardrail in the
harness is a guarantee. Anything below that we could move into the harness, we did.
## Authorization is not this tool's job — decide it where it belongs
Whether a write should happen is your decision, or the account's. The tool does
not gate it — there is no read-only switch and no approval prompt to configure.
The two right places to control read vs write:
- **The token you connect with.** Give it a GitLab/Gitea access token without
write scope. A write then fails at the server, which is the only place the
permission actually lives — no skill-side flag can be argued around by a
model, but a token without the scope cannot be.
- **Your agent's system prompt.** If you want an observe-only session, tell the
model not to call the write tools (they are clearly tagged `[WRITE]`).
What the tool *does* guarantee is that you can always see what happened:
## What the tool enforces — do not waste prompt budget on these
| You might be tempted to prompt | Why you don't need to |
|---|---|
| "Log everything you do, over both MCP and the CLI" | Every call is audited to `~/.cicd-aiops/audit.db` regardless of what the model says it did — and the CLI writes the same row the MCP path does, so there is no unaudited entry point. Reversible writes also record an undo token capturing the *prior* state. |
| "Don't invent a value when a field is missing" | A field the server did not return comes back as `null`, never as `""`. A pipeline with no `ref`, a job with no `startedAt` or `failureReason`, a runner that has never reported `contactedAt` — all stay `null`, and the key is always present. |
| "Tell me if the output was cut off" | Every listing returns `{"<items>": [...], "returned": N, "limit": L, "truncated": true/false}`. Truncation is **measured** (one extra row is fetched), never guessed from a full page. `job_trace_tail` adds `charsTruncated` for the byte ceiling. |
| "Tell me if a number is unknown rather than zero" | Storage numbers a platform does not report come back as `null` with `artifactsBytesKnown: false`, and `artifact_storage_bloat_analysis` counts them in `artifactBytesUnavailable`. `cicd_overview` reports `runnersSupported`. |
| "Confirm before anything destructive" | Destructive operations require a `--dry-run`-able preview + double confirmation at the CLI. |
| "Don't get stuck retrying" | The runaway guard trips a circuit breaker if the same call is hammered in a tight loop — a stuck agent is stopped rather than left to burn calls and timreferences/capabilities.md
# cicd-aiops — capabilities reference
28 governed MCP tools over two platforms (16 reads + 4 analyses + 6 writes +
`undo_list`/`undo_apply`). Every tool takes an optional
`target` (a name from `~/.cicd-aiops/config.yaml`); writes also take
`dry_run: bool`.
## Platforms
| Platform | API | Auth | Project addressing |
|---|---|---|---|
| `gitlab` | REST v4 (`/api/v4/...`) | `PRIVATE-TOKEN: <token>` | numeric id or URL-encoded full path (`group%2Fproject`) |
| `gitea` | API v1 (`/api/v1/...`) | `Authorization: token <token>` | `owner/repo` (two path segments) |
Self-managed/self-hosted instances only. Where Gitea lacks a surface, the
platform registry raises a teaching `KeyError` naming the resources that ARE
available: runner administration, pipeline retry/cancel, and artifact deletion
are GitLab-only in v0.1.
## Reads (16)
| Tool | What it returns | GitLab path | Gitea path |
|---|---|---|---|
| `server_version` | version + revision | `/api/v4/version` | `/api/v1/version` |
| `current_user` | token identity (scope probe) | `/api/v4/user` | `/api/v1/user` |
| `cicd_overview` | version + identity + projects + runners | (composite) | (composite) |
| `list_projects` | projects w/ storage bytes | `/api/v4/projects?statistics=true` | `/api/v1/repos/search` |
| `project_detail` | one project incl. sizes | `/api/v4/projects/{p}` | `/api/v1/repos/{owner}/{repo}` |
| `list_pipelines` | recent pipelines/runs | `/api/v4/projects/{p}/pipelines` | **unsupported** — Gitea API v1 has no run-level resource |
| `pipeline_detail` | one pipeline/run | `.../pipelines/{id}` | **unsupported** (same reason) |
| `pipeline_jobs` | jobs + failure_reason | `.../pipelines/{id}/jobs` | **unsupported**; the per-job listing is `/actions/tasks` |
| `job_trace_tail` | last N log lines | `.../jobs/{id}/trace` | `.../actions/jobs/{id}/logs` |
| `list_runners` | fleet, offline first | `/api/v4/runners/all` | — teaching error |
| `runner_detail` | contacted_at, tags, paused | `/api/v4/runners/{id}` | — teaching error |
| `list_merge_requests` | MRs / PRs | `.../merge_requests` | `.../pulls` |
| `list_branches` | branches + last-commit date | `.../repository/branches` | `.../branches` |
| `list_protected_branches` | protection rules + force-push flags | `.../protected_branches` | `.../branch_protections` |
| `list_releases` | releases newest first | `.../releases` | `.../releases` |
| `list_artifacts` | files, sizes, expiry, expired-but-kept | via `.../jobs` artifacts | `.../actions/artifacts` |
## Flagship analyses (4, read-only, thresholds are parameters)
| Tool | Flags | Key thresholds |
|---|---|---|
| `pipeline_failure_rca` | each failed job classified: test-failure / dependency-network / runner-timeout / oom / script-error, with matched evidence + action | `limit` (pipelines), `tail_lines` |
| `runner_health_rca` | offline / stale / paused runners; long-queued jobs; saturated tags | `stale_contact_min` (30), `queue_sec` (300), `saturation_ratio` (2.0) |
| `artifact_storagereferences/cli-reference.md
# cicd-aiops — CLI reference All commands accept `--target/-t <name>` (default: the first target in config.yaml). Writes accept `--dry-run` and double-confirm before executing; confirmed writes run through the same governed path as the MCP tools (audited). ## Setup / health ```bash cicd-aiops init # onboarding wizard (platform, base URL, encrypted token) cicd-aiops doctor # config + secrets + connectivity + token-scope probe cicd-aiops doctor --skip-auth # config/secrets checks only cicd-aiops overview # version, identity, projects, runners cicd-aiops projects [--search x] [--limit N] ``` ## Pipelines ```bash cicd-aiops pipelines list <project> [--status failed] [--limit N] cicd-aiops pipelines show <project> <pipeline> cicd-aiops pipelines jobs <project> <pipeline> cicd-aiops pipelines trace <project> <job> [--lines 60] cicd-aiops pipelines retry <project> <pipeline> [--dry-run] # governed write cicd-aiops pipelines cancel <project> <pipeline> [--dry-run] # governed write ``` ## Runners ```bash cicd-aiops runners list [--status offline] cicd-aiops runners show <runner> cicd-aiops runners pause <runner> [--dry-run] # governed write, undo-recorded cicd-aiops runners resume <runner> [--dry-run] # governed write, undo-recorded ``` ## Artifacts ```bash cicd-aiops artifacts list <project> cicd-aiops artifacts delete <project> [--older-than-days 30] [--dry-run] # risk=high: requires CICD_AUDIT_APPROVED_BY (+ CICD_AUDIT_RATIONALE) ``` ## Flagship RCAs ```bash cicd-aiops rca pipelines <project> [--limit 10] # classify failed pipelines cicd-aiops rca runners # offline/stale/saturation cicd-aiops rca storage [--old-days 30] # bloat + reclaimable bytes cicd-aiops rca stale <project> [--mr-days 14] [--branch-days 90] ``` ## Secrets ```bash cicd-aiops secret set <target> # store a token (encrypted) cicd-aiops secret list # names only, never values cicd-aiops secret remove <target> cicd-aiops secret migrate # legacy .env → encrypted store ``` ## MCP ```bash cicd-aiops mcp # start the MCP server (stdio) ``` ## Environment variables | Var | Purpose | |---|---| | `CICD_AIOPS_HOME` | relocate config/audit/undo/secrets (default `~/.cicd-aiops`) | | `CICD_AIOPS_CONFIG` | explicit config.yaml path for the MCP server | | `CICD_AIOPS_MASTER_PASSWORD` | unlock secrets.enc non-interactively | | `CICD_AUDIT_APPROVED_BY` / `CICD_AUDIT_RATIONALE` | optional audit annotations (who/why) — recorded, never required | | `CICD_MAX_TOOL_CALLS` / `CICD_MAX_TOOL_SECONDS` | budget caps | | `CICD_RUNAWAY_MAX` / `CICD_RUNAWAY_WINDOW_SEC` | runaway breaker | | `CICD_<TARGET>_SECRET` | legacy plaintext token fallback (deprecated) |
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/zw008/skills/cicd-aiops",
"sourceUrl": "https://clawhub.ai/zw008/skills/cicd-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T07:30:40.929Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-cicd-aiops/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-cicd-aiops/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-10T07:30:40.929Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.6K downloads",
"href": "https://clawhub.ai/zw008/cicd-aiops",
"sourceUrl": "https://clawhub.ai/zw008/cicd-aiops",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-10T07:30:40.929Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.10.3",
"href": "https://clawhub.ai/zw008/cicd-aiops",
"sourceUrl": "https://clawhub.ai/zw008/cicd-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:48:31.953Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-cicd-aiops/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-zw008-cicd-aiops/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.10.3",
"description": "- Removed the file skill-card.md. - No functional or user-facing changes in this release.",
"href": "https://clawhub.ai/zw008/cicd-aiops",
"sourceUrl": "https://clawhub.ai/zw008/cicd-aiops",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-15T05:48:31.953Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
