Agent skill

GitHub GitLab

by yc-software in yc-software/qm

Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

MITAuto-check passedDevelopment

Install GitHub GitLab

skills CLI
$ npx skills add yc-software/qm --skill github-gitlab -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yc-software/qm github-gitlab --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-seed/github-gitlab .claude/skills/github-gitlab && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-gitlab
GitHub stars
15k
Token cost
~1.6k tokens
SKILL.md length
793 words
Files
2 (incl. scripts)
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

  • Development work in your project
  • SKILL.md covers Choose the account deliberately, Logging in, Read-only work and Checkout and edits, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls gh, glab and git

What it does

GitHub GitLab is an agent skill from yc-software/qm. Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.

It sits in Development. It works with GitHub, GitLab and Git. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/github-gitlab”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 23af31b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • gh
    • glab
    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, glab and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitHub GitLab loads about 1.6k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 793 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from yc-software/qm at commit 23af31b, republished under its MIT licence (© yc-software). 793 words, ~1,571 tokens.

Download SKILL.mdSave it as .claude/skills/github-gitlab/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
github-gitlab
description
Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
requiredCapabilities
egress:github.com, egress:api.github.com, egress:gitlab.com

GitHub / GitLab

Use this skill when the user asks to inspect repos, issues, pull requests, merge requests, code history, branches, or to make a small code change in a hosted repo.

Choose the account deliberately

Use the current credential manifest to choose an account authorized for this conversation that fits the user's intent. Personal and shared accounts are both valid choices; neither is an automatic fallback when the other fails. If the intended account is unclear before a write, ask. Do not infer permission from a login merely being present on the computer.

  • Personal login: use the authorized gh, glab, or Git login. Check the active provider account (for example, gh api user --jq .login) and the Git transport's auth configuration; a CLI API identity alone does not prove which account Git will use.
  • Shared org credential: if listed in the prompt, select its slug and use the core-hosted smart HTTP remote in the use-shared-credential skill. This uses the configured shared account, even when a personal OAuth connector is live. Its name is an admin label, not a verified upstream username.
  • Connected app: use only advertised capabilities. API access does not by itself establish native Git transport access or configure the CLI's active login.

For an existing checkout, inspect the remote and applicable credential-helper, SSH, proxy, and HTTP-header configuration. A reused checkout may still select a previous account. Commit author metadata is separate from transport identity. Resolve an unknown identity before a write; do not probe access by pushing.

Logging in

Use the native login only after an explicit authentication rejection. A TLS timeout, connection reset, rate limit, or GitHub server error is not evidence of logout or permission expiry. Do not consume another credential grant to repair transport.

For a confirmed missing or expired GitHub login:

bash
gh auth login

The platform recognizes this device-flow login and runs it as a durable process session (ADR 0002): it prints the one-time code + verification URL immediately and keeps polling on the agent computer across turns — it does not block your turn or die at teardown. Give the user the code and URL, ask them to approve in the browser, then say "done". On the next turn, run gh auth status (or gh auth login again): the platform reports you're authenticated once approval completes, and the login self-expires if the user takes too long (just run gh auth login again to restart). GitLab is the same with glab auth login.

Read-only work

Check auth and inspect repo state:

bash
gh auth status
gh repo view OWNER/REPO --json name,description,url,defaultBranchRef
gh issue list --repo OWNER/REPO --state open --limit 20
gh pr list --repo OWNER/REPO --state open --limit 20

For GitLab:

bash
glab auth status
glab repo view GROUP/PROJECT
glab issue list --repo GROUP/PROJECT
glab mr list --repo GROUP/PROJECT

Use git log, git show, and git diff for codebase-change summaries. Cite commit hashes, PR/MR numbers, and links.

Checkout and edits

Clone or fetch only the repo the user asked for:

bash
gh repo clone OWNER/REPO repo
cd repo
git checkout -b codex/small-change

Keep changes scoped. Run the repo's tests. If a push or PR/MR creation is requested, prepare the branch and summary first.

Show full SKILL.md (327 more words)Show less

Writes require approval

Pushing branches, creating PRs/MRs, merging, closing issues, editing labels, changing repo settings, releases, or workflows are writes. Ask for approval before running the write command.

After approval:

bash
git push -u origin codex/small-change
gh pr create --repo OWNER/REPO --title "..." --body-file pr.md

For GitLab:

bash
git push -u origin codex/small-change
glab mr create --repo GROUP/PROJECT --title "..." --description-file mr.md

Report the final URL and leave enough context for review.

Wait for GitHub CI

Use the bundled helper instead of a bare gh pr checks --watch or a handwritten shell loop. It is one blocking watcher process, not repeated agent turns:

bash
node skills/github-gitlab/scripts/watch-ci.mjs --repo OWNER/REPO --pr NUMBER --head REVIEWED_HEAD_SHA

Capture the full head SHA from gh pr view NUMBER --repo OWNER/REPO --json headRefOid before review. Use that same SHA for the watcher and the final merge gate. Start the watcher with the background-process tool and subscribe to its completion. Keep one watcher per PR. Set the process lifetime longer than the helper's 30-minute deadline; use --timeout-ms for a different bounded deadline. Use only credentials authorized for that background process; a live foreground grant does not authorize background work.

The helper polls GitHub internally and emits JSON status records. It retries only recognized transient transport/server errors with bounded backoff. Pending checks remain pending. Real CI failures, authentication/authorization failures, changed heads, unknown errors, exhausted retries, and deadline expiry all stop with nonzero status. Explicit API rate limits stop as rate_limited, not authentication errors. Empty check sets, skipped checks, and cancelled checks are not successful evidence. Do not interpret an exit code alone as "checks concluded": read the status record. Do not suppress a nonzero exit or print a success marker after it. Keep set -e.

Success means the checks observed for the expected head passed, not permission to merge. Re-read checks and review threads immediately before merging. Wait for async reviewers on that exact head; resolve findings and obtain a fresh-context adversarial review. After any push or head change, discard old success/review evidence and repeat. Only merge when all gates pass, with GitHub's atomic head guard:

bash
gh pr merge NUMBER --repo OWNER/REPO --squash --match-head-commit REVIEWED_HEAD_SHA

Never use auto-merge or bypass repository gates. This helper does not retry GitLab commands or change their authentication behavior.

© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills-seed/github-gitlab of yc-software/qm.

  • SKILL.md
  • scripts/watch-ci.mjs

Open the folder on GitHubat commit 23af31b

Compare with similar skills

GitHub GitLab next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub GitLab compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub GitLab this skillyc-software/qm15k—~1.6kAutomated safety check: PassMIT
Visual Reviewai-dynamo/dynamo8.2k—~4.5kAutomated safety check: PassApache-2.0
degit Project ScaffoldingRich-Harris/degit7.9k—~534Automated safety check: PassMIT
Greploop Appsmichaelshimeles/skills1.3k1 repos~3.6kAutomated safety check: PassMIT
Git MacheteVirtusLab/git-machete1.1k—~6.1kAutomated safety check: PassMIT
MR and PR Description Draftertabler/tabler42k—~2kAutomated safety check: PassMIT

Similar skills

  • Visual Review

    ai-dynamo/dynamo

    Create self-contained interactive HTML code-review dashboards from GitHub or GitLab pull requests, checked-out branch diffs, or supplied unified diffs, with correctness and safe-to-merge scores…

    8.2k GitHub stars~4.5k tokensUpdated today
    DevelopmentAuto-check passed
  • degit Project Scaffolding

    Rich-Harris/degit

    Downloads a repository snapshot or template with degit into an empty folder, from GitHub, GitLab, Bitbucket, Sourcehut or a Gist, optionally at a branch, tag or commit.

    7.9k GitHub stars~534 tokensUpdated 24 days ago
    DevelopmentAuto-check passed
  • Greploop Apps

    michaelshimeles/skills

    Loops on a large pull request, merge request or Perforce changelist, fixing Greptile findings until it scores 5/5 with no unresolved comments.

    1.3k GitHub starsUsed in 1 repo~3.6k tokens
    DevelopmentAuto-check passed
  • Git Machete

    VirtusLab/git-machete

    A skill your agent uses whenever invoking the git machete CLI to organize branch chains, compute fork points, run stacked rebases/merges, or manage GitHub/GitLab PR/MR chains - especially in a repo…

    1.1k GitHub stars~6.1k tokensUpdated 3 days ago
    DevelopmentAuto-check passed
  • Drafts a merge request or pull request title and body in simple English from the branch's git history and diff against origin/dev, ready to paste into GitLab or GitHub.

    42k GitHub stars~2k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Init Remote

    exception-coder/npe_get_jobs

    Initialize git in a local project without a repository, connect it to a remote, and generate a proper .gitignore.

    176 GitHub stars~662 tokensUpdated 14 days ago
    DevelopmentAuto-check passed

More from yc-software/qm

All 29 skills in this repo
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Browse

    yc-software/qm

    Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…

    15k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Composio

    yc-software/qm

    Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Dev Instance

    yc-software/qm

    Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.

    15k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • Google Workspace

    yc-software/qm

    Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.

    15k GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Memory

    yc-software/qm

    Deliberately search, add to, or curate your long-term memory with the memory tool — beyond the automatic recall/capture every turn already does.

    15k GitHub stars~1.2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about GitHub GitLab

What does GitHub GitLab do?

Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer. GitHub GitLab is an agent skill from yc-software/qm. Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

When should I use GitHub GitLab?

GitHub GitLab fits situations like: development work in your project.

How do I install GitHub GitLab in Claude Code?

Run `npx skills add yc-software/qm --skill github-gitlab -a claude-code`. Or copy the skill folder (skills-seed/github-gitlab in yc-software/qm) into .claude/skills/github-gitlab in your project. Claude Code loads it when a task matches its description.

How do I install GitHub GitLab in Codex?

Run `npx skills add yc-software/qm --skill github-gitlab -a codex`. Or copy the skill folder (skills-seed/github-gitlab in yc-software/qm) into .agents/skills/github-gitlab in your project. Codex loads it when a task matches its description.

Can I use GitHub GitLab in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill github-gitlab -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-gitlab, .gemini/skills/github-gitlab, .github/skills/github-gitlab and .opencode/skills/github-gitlab in your project.

What does GitHub GitLab need to run?

Going by SKILL.md and its folder, GitHub GitLab needs JavaScript for the scripts in its folder and the command-line tools its instructions call (gh, glab, git and node). Our summary lists: Node.js.

Does GitHub GitLab access the network?

SKILL.md contains no URLs. Its commands use gh and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitHub GitLab safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does GitHub GitLab use?

GitHub GitLab is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub GitLab use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub GitLab?

Skills that share tags, products or a category with GitHub GitLab: Visual Review (ai-dynamo/dynamo, 8.2k stars), degit Project Scaffolding (Rich-Harris/degit, 7.9k stars), Greploop Apps (michaelshimeles/skills, 1.3k stars) and Git Machete (VirtusLab/git-machete, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub GitLab?

yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,357 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 6, 2026.

Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.