Visual Review
ai-dynamo/dynamo
Create self-contained interactive HTML code-review dashboards from GitHub or GitLab pull requests, checked-out branch diffs, or supplied unified diffs, with correctness and safe-to-merge scores…
Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
$ npx skills add yc-software/qm --skill github-gitlab -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yc-software/qm github-gitlab --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-seed/github-gitlab .claude/skills/github-gitlab && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .claude/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlabType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yc-software/qm --skill github-gitlab -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yc-software/qm github-gitlab --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills-seed/github-gitlab .agents/skills/github-gitlab && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .agents/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yc-software/qm --skill github-gitlab -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yc-software/qm github-gitlab --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills-seed/github-gitlab .cursor/skills/github-gitlab && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .cursor/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yc-software/qm.git --path skills-seed/github-gitlab--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yc-software/qm --skill github-gitlab -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yc-software/qm github-gitlab --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills-seed/github-gitlab .gemini/skills/github-gitlab && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .gemini/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yc-software/qm github-gitlabInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yc-software/qm --skill github-gitlab -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills-seed/github-gitlab .github/skills/github-gitlab && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .github/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yc-software/qm --skill github-gitlab -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yc-software/qm github-gitlab --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills-seed/github-gitlab .opencode/skills/github-gitlab && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-gitlab" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/github-gitlab into .opencode/skills/github-gitlab/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-gitlab", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-gitlabWork with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
GitHub GitLab is an agent skill from yc-software/qm. Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in Development. It works with GitHub, GitLab and Git. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.
Read from SKILL.md and the folder at commit 23af31b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
ghglabgitnodeFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh, glab and git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub GitLab loads about 1.6k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 793 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from yc-software/qm at commit 23af31b, republished under its MIT licence (© yc-software). 793 words, ~1,571 tokens.
.claude/skills/github-gitlab/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Use this skill when the user asks to inspect repos, issues, pull requests, merge requests, code history, branches, or to make a small code change in a hosted repo.
Use the current credential manifest to choose an account authorized for this conversation that fits the user's intent. Personal and shared accounts are both valid choices; neither is an automatic fallback when the other fails. If the intended account is unclear before a write, ask. Do not infer permission from a login merely being present on the computer.
gh, glab, or Git login. Check the active
provider account (for example, gh api user --jq .login) and the Git transport's auth
configuration; a CLI API identity alone does not prove which account Git will use.use-shared-credential skill. This uses
the configured shared account, even when a personal OAuth connector is live.
Its name is an admin label, not a verified upstream username.For an existing checkout, inspect the remote and applicable credential-helper, SSH, proxy, and HTTP-header configuration. A reused checkout may still select a previous account. Commit author metadata is separate from transport identity. Resolve an unknown identity before a write; do not probe access by pushing.
Use the native login only after an explicit authentication rejection. A TLS timeout, connection reset, rate limit, or GitHub server error is not evidence of logout or permission expiry. Do not consume another credential grant to repair transport.
For a confirmed missing or expired GitHub login:
gh auth loginThe platform recognizes this device-flow login and runs it as a durable process
session (ADR 0002): it prints the one-time code + verification URL immediately and keeps
polling on the agent computer across turns — it does not block your turn or die at
teardown. Give the user the code and URL, ask them to approve in the browser, then say
"done". On the next turn, run gh auth status (or gh auth login again): the platform
reports you're authenticated once approval completes, and the login self-expires if the
user takes too long (just run gh auth login again to restart). GitLab is the same with
glab auth login.
Check auth and inspect repo state:
gh auth status
gh repo view OWNER/REPO --json name,description,url,defaultBranchRef
gh issue list --repo OWNER/REPO --state open --limit 20
gh pr list --repo OWNER/REPO --state open --limit 20For GitLab:
glab auth status
glab repo view GROUP/PROJECT
glab issue list --repo GROUP/PROJECT
glab mr list --repo GROUP/PROJECTUse git log, git show, and git diff for codebase-change summaries. Cite commit
hashes, PR/MR numbers, and links.
Clone or fetch only the repo the user asked for:
gh repo clone OWNER/REPO repo
cd repo
git checkout -b codex/small-changeKeep changes scoped. Run the repo's tests. If a push or PR/MR creation is requested, prepare the branch and summary first.
Pushing branches, creating PRs/MRs, merging, closing issues, editing labels, changing repo settings, releases, or workflows are writes. Ask for approval before running the write command.
After approval:
git push -u origin codex/small-change
gh pr create --repo OWNER/REPO --title "..." --body-file pr.mdFor GitLab:
git push -u origin codex/small-change
glab mr create --repo GROUP/PROJECT --title "..." --description-file mr.mdReport the final URL and leave enough context for review.
Use the bundled helper instead of a bare gh pr checks --watch or a handwritten
shell loop. It is one blocking watcher process, not repeated agent turns:
node skills/github-gitlab/scripts/watch-ci.mjs --repo OWNER/REPO --pr NUMBER --head REVIEWED_HEAD_SHACapture the full head SHA from gh pr view NUMBER --repo OWNER/REPO --json headRefOid
before review. Use that same SHA for the watcher and the final merge gate. Start the
watcher with the background-process tool and subscribe to its completion. Keep one
watcher per PR. Set the process lifetime longer than the helper's 30-minute deadline;
use --timeout-ms for a different bounded deadline. Use only credentials authorized
for that background process; a live foreground grant does not authorize background work.
The helper polls GitHub internally and emits JSON status records. It retries only
recognized transient transport/server errors with bounded backoff. Pending checks
remain pending. Real CI failures, authentication/authorization failures, changed heads,
unknown errors, exhausted retries, and deadline expiry all stop with nonzero status.
Explicit API rate limits stop as rate_limited, not authentication errors.
Empty check sets, skipped checks, and cancelled checks are not successful evidence.
Do not interpret an exit code alone as "checks concluded": read the status record.
Do not suppress a nonzero exit or print a success marker after it. Keep set -e.
Success means the checks observed for the expected head passed, not permission to merge. Re-read checks and review threads immediately before merging. Wait for async reviewers on that exact head; resolve findings and obtain a fresh-context adversarial review. After any push or head change, discard old success/review evidence and repeat. Only merge when all gates pass, with GitHub's atomic head guard:
gh pr merge NUMBER --repo OWNER/REPO --squash --match-head-commit REVIEWED_HEAD_SHANever use auto-merge or bypass repository gates. This helper does not retry GitLab commands or change their authentication behavior.
© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skills-seed/github-gitlab of yc-software/qm.
Open the folder on GitHubat commit 23af31b
GitHub GitLab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub GitLab this skillyc-software/qm | 15k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Visual Reviewai-dynamo/dynamo | 8.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 | |
| degit Project ScaffoldingRich-Harris/degit | 7.9k | — | ~534 | Automated safety check: Pass | MIT | |
| Greploop Appsmichaelshimeles/skills | 1.3k | 1 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Git MacheteVirtusLab/git-machete | 1.1k | — | ~6.1k | Automated safety check: Pass | MIT | |
| MR and PR Description Draftertabler/tabler | 42k | — | ~2k | Automated safety check: Pass | MIT |
ai-dynamo/dynamo
Create self-contained interactive HTML code-review dashboards from GitHub or GitLab pull requests, checked-out branch diffs, or supplied unified diffs, with correctness and safe-to-merge scores…
Rich-Harris/degit
Downloads a repository snapshot or template with degit into an empty folder, from GitHub, GitLab, Bitbucket, Sourcehut or a Gist, optionally at a branch, tag or commit.
michaelshimeles/skills
Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.
VirtusLab/git-machete
A skill your agent uses whenever invoking the git machete CLI to organize branch chains, compute fork points, run stacked rebases/merges, or manage GitHub/GitLab PR/MR chains - especially in a repo…
tabler/tabler
Drafts a merge request or pull request title and body in simple English from the branch's git history and diff against origin/dev, ready to paste into GitLab or GitHub.
exception-coder/npe_get_jobs
Initialize git in a local project without a repository, connect it to a remote, and generate a proper .gitignore.
yc-software/qm
Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…
yc-software/qm
Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…
yc-software/qm
Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.
yc-software/qm
Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.
yc-software/qm
Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.
yc-software/qm
Deliberately search, add to, or curate your long-term memory with the memory tool — beyond the automatic recall/capture every turn already does.
Categories
Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer. GitHub GitLab is an agent skill from yc-software/qm. Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
GitHub GitLab fits situations like: development work in your project.
Run `npx skills add yc-software/qm --skill github-gitlab -a claude-code`. Or copy the skill folder (skills-seed/github-gitlab in yc-software/qm) into .claude/skills/github-gitlab in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yc-software/qm --skill github-gitlab -a codex`. Or copy the skill folder (skills-seed/github-gitlab in yc-software/qm) into .agents/skills/github-gitlab in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill github-gitlab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-gitlab, .gemini/skills/github-gitlab, .github/skills/github-gitlab and .opencode/skills/github-gitlab in your project.
Going by SKILL.md and its folder, GitHub GitLab needs JavaScript for the scripts in its folder and the command-line tools its instructions call (gh, glab, git and node). Our summary lists: Node.js.
SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
GitHub GitLab is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub GitLab: Visual Review (ai-dynamo/dynamo, 8.2k stars), degit Project Scaffolding (Rich-Harris/degit, 7.9k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Git Machete (VirtusLab/git-machete, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,357 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 6, 2026.
Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.