Agent skill

GitLab CI Validator

by akin-ozer in akin-ozer/cc-devops-skills

Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.

Apache-2.0Auto-check passedDevOps & Cloud

Install GitLab CI Validator

skills CLI
$ npx skills add akin-ozer/cc-devops-skills --skill gitlab-ci-validator -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install akin-ozer/cc-devops-skills gitlab-ci-validator --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/akin-ozer/cc-devops-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/devops-skills-plugin/skills/gitlab-ci-validator .claude/skills/gitlab-ci-validator && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gitlab-ci-validator
GitHub stars
319
Token cost
~1.6k tokens
SKILL.md length
454 words
Files
24 (incl. scripts)
Skills in repo
30
Repo updated
First seen
Licence
Apache-2.0

At a glance

Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.

  • Works in 6 steps: Run Quick Start command 2 (--syntax-only). → If syntax fails, stop and fix errors… → Run Quick Start command 3… → …
  • Tasks that involve CI/CD
  • SKILL.md covers Trigger Phrases, Setup And Prerequisites (Run…, Quick Start Commands and Deterministic Validation…, plus 6 more sections
  • Calls bash and python3

What it does

GitLab CI Validator is an agent skill from akin-ozer/cc-devops-skills. Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 37 other files, including scripts (for example `docs/best-practices.md`, `docs/common-issues.md` and `docs/gitlab-ci-reference.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with GitLab. The repository describes itself as: DevOps skills for Claude Code and Codex. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve CI/CD

Example prompts

  • “/gitlab-ci-validator”

Requirements

  • Python 3
  • Docker

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Run Quick Start command 2 (--syntax-only).
  2. If syntax fails, stop and fix errors before continuing.
  3. Run Quick Start command 3 (--best-practices) and apply relevant improvements.
  4. Run Quick Start command 4 (--security-only) and fix all critical/high findings before merge.
  5. Optionally run Quick Start command 5 (--test-only) for local execution checks.
  6. Run Quick Start command 6 (--strict) for final merge gate.

What it can do on your machine

Read from SKILL.md and the folder at commit 276af75. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/, which the agent can run.

    Shell commands in SKILL.md call:

    • bash
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.gitlab.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitLab CI Validator loads about 1.6k tokens when it runs. Until then it costs about 23 tokens; SKILL.md has 454 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~23
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from akin-ozer/cc-devops-skills at commit 276af75, republished under its Apache-2.0 licence (© akin-ozer). 454 words, ~1,616 tokens.

Download SKILL.mdSave it as .claude/skills/gitlab-ci-validator/SKILL.md (or your agent's skills folder). This skill also uses 23 other files; get the full folder from GitHub.
name
gitlab-ci-validator
description
Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs.

GitLab CI/CD Validator

Comprehensive toolkit for validating, linting, testing, and securing .gitlab-ci.yml configurations.

Trigger Phrases

Use this skill when requests include intent like:

  • "Validate this .gitlab-ci.yml"
  • "Why is this GitLab pipeline failing?"
  • "Run a security review for our GitLab CI"
  • "Check pipeline best practices"
  • "Lint GitLab CI config before merge"

Setup And Prerequisites (Run First)

All commands below assume repository root as current working directory.

bash
# Ensure validator scripts are executable
chmod +x devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.py

# Required runtime
python3 --version

Use one canonical command path for orchestration:

bash
VALIDATOR="bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_gitlab_ci.sh"

Optional local execution tooling (for --test-only):

bash
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/install_tools.sh

Quick Start Commands

bash
# 1) Full validation (syntax + best practices + security)
$VALIDATOR .gitlab-ci.yml

# 2) Syntax and schema only (required first gate)
$VALIDATOR .gitlab-ci.yml --syntax-only

# 3) Best-practices only (recommended)
$VALIDATOR .gitlab-ci.yml --best-practices

# 4) Security only (required before merge)
$VALIDATOR .gitlab-ci.yml --security-only

# 5) Optional local pipeline structure test (needs gitlab-ci-local + Docker)
$VALIDATOR .gitlab-ci.yml --test-only

# 6) Strict mode (treat best-practice warnings as failure)
$VALIDATOR .gitlab-ci.yml --strict

Deterministic Validation Workflow

Follow these gates in order:

  1. Run Quick Start command 2 (--syntax-only).
  2. If syntax fails, stop and fix errors before continuing.
  3. Run Quick Start command 3 (--best-practices) and apply relevant improvements.
  4. Run Quick Start command 4 (--security-only) and fix all critical/high findings before merge.
  5. Optionally run Quick Start command 5 (--test-only) for local execution checks.
  6. Run Quick Start command 6 (--strict) for final merge gate.

Required gates: syntax + security. Recommended gate: best practices. Optional gate: local execution test.

Severity Model
  • critical: Direct credential/secret exposure or high-confidence compromise path. Block merge.
  • high: Exploitable unsafe behavior or strong security regression. Fix before merge.
  • medium: Security hardening gap with realistic risk. Track and fix soon.
  • low/suggestion: Optimization or maintainability improvement.
Rule Classes And Why They Matter
  • Syntax rules (yaml-syntax, job-stage-undefined, dependencies-undefined-job): prevent pipeline parse and dependency failures.
  • Best-practice rules (cache-missing, artifact-no-expiration, dag-optimization): reduce runtime cost and improve pipeline throughput.
  • Security rules (hardcoded-password, curl-pipe-bash, include-remote-unverified): reduce credential leaks and supply-chain risk.
References
Show full SKILL.md (175 more words)Show less

Fallbacks For Tool Or Environment Constraints

  • Missing python3:
    • Behavior: validator cannot run.
    • Fallback: install Python 3 and rerun.
  • Missing PyYAML:
    • Behavior: python_wrapper.sh auto-creates .venv and installs pyyaml when possible.
    • Fallback in restricted/offline environments: pre-install pyyaml from an internal mirror, then rerun.
  • Missing gitlab-ci-local, node, or docker:
    • Behavior: --test-only reports warning/failure.
    • Fallback: skip local execution testing and continue with syntax/best-practice/security gates.
  • No execute permission on scripts:
    • Behavior: shell permission errors.
    • Fallback: rerun the setup chmod command from the Setup section.

Examples

Example 1: New Pipeline Validation
bash
$VALIDATOR examples/basic-pipeline.gitlab-ci.yml --syntax-only
$VALIDATOR examples/basic-pipeline.gitlab-ci.yml --security-only
Example 2: Pre-Merge Hard Gate
bash
$VALIDATOR .gitlab-ci.yml --strict
Example 3: CI Integration
yaml
stages:
  - validate

validate_gitlab_ci:
  stage: validate
  script:
    - chmod +x devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.sh devops-skills-plugin/skills/gitlab-ci-validator/scripts/*.py
    - bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_gitlab_ci.sh .gitlab-ci.yml --strict

Individual Validators (Advanced)

bash
# Syntax validator (via wrapper for PyYAML fallback)
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/validate_syntax.py .gitlab-ci.yml

# Best-practices validator
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/check_best_practices.py .gitlab-ci.yml

# Security validator
bash devops-skills-plugin/skills/gitlab-ci-validator/scripts/python_wrapper.sh \
  devops-skills-plugin/skills/gitlab-ci-validator/scripts/check_security.py .gitlab-ci.yml

Done Criteria

  • Frontmatter name and description unchanged.
  • One canonical orchestrator path is used consistently.
  • Setup and chmod prerequisites appear before workflow/use examples.
  • Quick-start and workflow are non-duplicative (workflow references quick-start gates).
  • Severity rationale and rule-to-doc references are explicit.
  • Fallback behavior is documented for missing tools and constrained environments.
  • Examples are executable from repository root.

Notes

  • This skill validates configuration and static patterns; it does not execute production pipelines.
  • Use gitlab-ci-local or GitLab CI Lint for runtime behavior confirmation.

© akin-ozer, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 23 other files (scripts) in devops-skills-plugin/skills/gitlab-ci-validator of akin-ozer/cc-devops-skills.

  • SKILL.md
  • .gitignore
  • docs/best-practices.md
  • docs/common-issues.md
  • docs/gitlab-ci-reference.md
  • examples/.gitlab-ci-local/expanded-gitlab-ci.yml
  • examples/.gitlab-ci-local/includes/gitlab.com/gitlab-org/gitlab/-/raw/HEAD/lib/gitlab/ci/templates/Jobs
  • … and 17 more

Open the folder on GitHubat commit 276af75

Compare with similar skills

GitLab CI Validator next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitLab CI Validator compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitLab CI Validator this skillakin-ozer/cc-devops-skills319—~1.6kAutomated safety check: PassApache-2.0
Fingerprint CI Gateliarjsdev/liarjs-skills5181 repos~986Automated safety check: NotesMIT
Megatron-LM Base Image BumpNVIDIA/Megatron-LM18k—~2.8kAutomated safety check: PassApache-2.0
Megatron-LM CI/CD GuideNVIDIA/Megatron-LM18k—~1.8kAutomated safety check: PassApache-2.0
Megalinter Checknvuillam/npm-groovy-lint2481 repos~3.9kAutomated safety check: NotesMIT
Migrate To TeamcityJetBrains/teamcity-cli125—~1.3kAutomated safety check: PassApache-2.0

Similar skills

  • Fingerprint CI Gate

    liarjsdev/liarjs-skills

    Gate a build on browser fingerprint regressions with liarjs - save a baseline scan as JSON, diff later runs against it, and fail the job when the consistency score falls below a floor.

    518 GitHub starsUsed in 1 repo~986 tokens
    DevOps & CloudAuto-check: notes
  • Megatron-LM Base Image Bump

    NVIDIA/Megatron-LM

    Official

    Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.

    18k GitHub stars~2.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Megatron-LM CI/CD Guide

    NVIDIA/Megatron-LM

    Official

    Explains Megatron-LM's CI pipeline, PR scope labels, triggering the internal GitLab CI with a dry run first, and investigating CI failures.

    18k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Megalinter Check

    nvuillam/npm-groovy-lint

    Collect MegaLinter lint errors for the current repository. An agent skill from nvuillam/npm-groovy-lint.

    248 GitHub starsUsed in 1 repo~3.9k tokens
    DevOps & CloudAuto-check: notes
  • Migrate To Teamcity

    JetBrains/teamcity-cli

    Official

    Migrating CI/CD pipelines to TeamCity. An agent skill from JetBrains/teamcity-cli.

    125 GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • GitLab Explorer

    Wide-Moat/open-computer-use

    Explore GitLab repositories using glab CLI and git commands.

    126 GitHub stars~891 tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from akin-ozer/cc-devops-skills

All 30 skills in this repo
  • GitHub Actions Generator

    akin-ozer/cc-devops-skills

    Create, generate, or scaffold GitHub Actions workflows, action.yml, or .github/workflows CI/CD pipelines.

    319 GitHub stars~3.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Helm Generator

    akin-ozer/cc-devops-skills

    Create, scaffold, or generate Helm charts, Chart.yaml, values.yaml, templates, helpers.

    319 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Generator

    akin-ozer/cc-devops-skills

    Generate/create/scaffold Jenkinsfile — declarative, scripted, shared library, CI/CD pipelines.

    319 GitHub stars~3.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Dockerfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or scan a Dockerfile for security and best practices.

    319 GitHub stars~2.3k tokensUpdated 2 mo ago
    Auto-check passed
  • GitHub Actions Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, fix GitHub Actions workflows (.github/workflows).

    319 GitHub stars~4.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Jenkinsfile Validator

    akin-ozer/cc-devops-skills

    Validate, lint, audit, or check Jenkinsfiles and shared libraries.

    319 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about GitLab CI Validator

What does GitLab CI Validator do?

Validate, lint, audit, or fix .gitlab-ci.yml pipelines, stages, and jobs. GitLab CI Validator is an agent skill from akin-ozer/cc-devops-skills.yml pipelines, stages, and jobs.

When should I use GitLab CI Validator?

GitLab CI Validator fits situations like: tasks that involve CI/CD.

How do I install GitLab CI Validator in Claude Code?

Run `npx skills add akin-ozer/cc-devops-skills --skill gitlab-ci-validator -a claude-code`. Or copy the skill folder (devops-skills-plugin/skills/gitlab-ci-validator in akin-ozer/cc-devops-skills) into .claude/skills/gitlab-ci-validator in your project. Claude Code loads it when a task matches its description.

How do I install GitLab CI Validator in Codex?

Run `npx skills add akin-ozer/cc-devops-skills --skill gitlab-ci-validator -a codex`. Or copy the skill folder (devops-skills-plugin/skills/gitlab-ci-validator in akin-ozer/cc-devops-skills) into .agents/skills/gitlab-ci-validator in your project. Codex loads it when a task matches its description.

Can I use GitLab CI Validator in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add akin-ozer/cc-devops-skills --skill gitlab-ci-validator -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitlab-ci-validator, .gemini/skills/gitlab-ci-validator, .github/skills/gitlab-ci-validator and .opencode/skills/gitlab-ci-validator in your project.

What does GitLab CI Validator need to run?

Going by SKILL.md and its folder, GitLab CI Validator needs the command-line tools its instructions call (bash and python3). Our summary lists: Python 3; Docker.

Does GitLab CI Validator access the network?

SKILL.md names 1 domain. As links in the text: docs.gitlab.com. This is read from the text; nothing was executed.

Is GitLab CI Validator safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does GitLab CI Validator use?

GitLab CI Validator is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitLab CI Validator use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitLab CI Validator?

Skills that share tags, products or a category with GitLab CI Validator: Fingerprint CI Gate (liarjsdev/liarjs-skills, 518 stars), Megatron-LM Base Image Bump (NVIDIA/Megatron-LM, 18k stars), Megatron-LM CI/CD Guide (NVIDIA/Megatron-LM, 18k stars) and Megalinter Check (nvuillam/npm-groovy-lint, 248 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitLab CI Validator?

akin-ozer (a GitHub user) maintains it in akin-ozer/cc-devops-skills, which has 319 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on July 26, 2026.

Source: akin-ozer/cc-devops-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.