Agent skill

GitLab CLI Without MCP

by zereight in zereight/gitlab-mcp

Authenticates and runs zereight-mcp-gitlab as a plain command line tool to read GitLab merge requests, diffs, discussions, issues and pipelines when no MCP client is set up.

MITAuto-check passedAgent Workflows

Install GitLab CLI Without MCP

skills CLI
$ npx skills add zereight/gitlab-mcp --skill gl-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install zereight/gitlab-mcp gl-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/zereight/gitlab-mcp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/gl-cli .claude/skills/gl-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gl-cli
GitHub stars
2k
Token cost
~787 tokens
SKILL.md length
352 words
Files
1
Skills in repo
24
Repo updated
First seen
Licence
MIT

At a glance

Authenticates and runs zereight-mcp-gitlab as a plain command line tool to read GitLab merge requests, diffs, discussions, issues and pipelines when no MCP client is set up.

  • Works in 3 steps: Check credentials first → Authenticate (ask the user which option) → Read merge requests
  • Reading a GitLab merge request, its diff or discussion threads without an MCP client
  • SKILL.md covers 1. Check credentials first, 2. Authenticate (ask the user…, 3. Read merge requests and Required input resolution, plus 2 more sections
  • Calls npm and git; needs GITLAB_PERSONAL_ACCESS_TOKEN

What it does

The same zereight-mcp-gitlab binary that serves as an MCP server also works as a GitLab CLI: run a command and it prints the result and exits, with no MCP client involved. The agent first runs user whoami to check credentials, and depending on the result either proceeds, asks the user to authenticate, or tells them to reinstall the package if the command is missing.

Authentication is never done on the agent's behalf: the user is asked to choose between a personal access token, read into an environment variable with a hidden prompt, or an OAuth device flow that needs a GitLab OAuth application ID, and a token is never passed with --token since process arguments are visible to other users.

Reading merge requests covers listing, viewing a summary, listing changed files, getting the full diff, reading discussion threads, pipelines and approval state, with --output json for parsing and a files-then-diff approach for large MRs. The project or MR number is taken from the user or discovered with mr list or git remote, never left as a placeholder. A read-only permission mode blocks approve, merge, note, update and create commands with exit code 2.

When your agent uses it

  • Reading a GitLab merge request, its diff or discussion threads without an MCP client
  • Checking pipeline status or approval state on a merge request from the terminal
  • Setting up CLI-only access to GitLab with a personal access token or OAuth

Example prompts

  • “List the open merge requests in this project using the GitLab CLI.”
  • “Show me the full diff and discussion threads for MR 482.”
  • “Check whether my GitLab credentials are set up for the CLI; walk me through authenticating if not.”

Requirements

  • The @zereight/mcp-gitlab package installed globally
  • A GitLab personal access token or an OAuth application ID

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Check credentials first
  2. Authenticate (ask the user which option)
  3. Read merge requests

What it can do on your machine

Read from SKILL.md and the folder at commit 0109168. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITLAB_PERSONAL_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

GitLab CLI Without MCP loads about 787 tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 352 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~787

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from zereight/gitlab-mcp at commit 0109168, republished under its MIT licence (© zereight). 352 words, ~787 tokens.

Download SKILL.mdSave it as .claude/skills/gl-cli/SKILL.md (or your agent's skills folder).
name
gl-cli
description
Use GitLab from the terminal without registering an MCP server. Covers authenticating the zereight-mcp-gitlab CLI (PAT or OAuth device flow) and reading merge requests, diffs, discussions, issues, and pipelines. Use when the user asks about a GitLab MR/issue/pipeline and no GitLab MCP tools are available, or wants CLI-only setup.

gl-cli

zereight-mcp-gitlab (alias mcp-gitlab) is both the MCP server and a GitLab CLI. Run it with a command and it prints the result and exits. No MCP client is involved.

Full guide: docs/getting-started/cli-without-mcp.md.

1. Check credentials first

Run this before anything else and read the result:

bash
zereight-mcp-gitlab user whoami
  • Prints a user: credentials work, go to step 3.
  • Missing GitLab credentials (exit 2): go to step 2.
  • 401: token expired or under-scoped, redo step 2.
  • command not found: npm install -g @zereight/mcp-gitlab.

2. Authenticate (ask the user which option)

Never invent, guess, or echo a token. Ask the user to run the command themselves, since it needs their secret.

A. Personal Access Token (fastest; scope read_api, or api to write)

bash
read -rs GITLAB_PERSONAL_ACCESS_TOKEN && export GITLAB_PERSONAL_ACCESS_TOKEN
export GITLAB_API_URL=https://gitlab.example.com/api/v4   # omit for gitlab.com

B. OAuth device flow (needs a GitLab OAuth application ID)

bash
export GITLAB_OAUTH_CLIENT_ID=YOUR_APP_ID
zereight-mcp-gitlab auth        # open the printed URL, enter the code
export GITLAB_USE_OAUTH=true    # needed on every later CLI call

Do not pass the token with --token; arguments are visible in ps.

3. Read merge requests

GoalCommand
List open MRsmr list --project-id <path|id> --state opened
MR summarymr view --project-id <p> --mr-iid <n>
Changed file paths onlymr files --project-id <p> --mr-iid <n>
Full diffmr diff --project-id <p> --mr-iid <n>
Review threadsmr discussions --project-id <p> --mr-iid <n>
MR pipelinesmr pipelines --project-id <p> --mr-iid <n>
Approval statemr approvals --project-id <p> --mr-iid <n>
Anything elsetool <tool_name> --project-id <p> --args-json '{...}'

Prefix every command with zereight-mcp-gitlab. Add --output json when parsing the result. For large MRs use mr files first, then diff only the files you need.

Show full SKILL.md (115 more words)Show less

Required input resolution

Never use placeholders like <project> or 42 from this table in a real call. If the project or MR number is missing, get it from the user, or discover it with mr list or git remote -v.

Safety

  • Default to read-only: export GITLAB_PERMISSION_MODE=readonly. Writes (mr approve, mr merge, mr note, mr update, mr create) are refused with exit 2.
  • Destructive commands need --yes. Only add it after the user confirms that exact action in the current message.
  • Do not run mr merge or mr approve unless the user named that action.

Not covered here

For the MCP tool catalog and workflows, use the gitlab-mcp skill. This skill is the CLI route only.

© zereight, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/gl-cli of zereight/gitlab-mcp.

Open the folder on GitHubat commit 0109168

Compare with similar skills

GitLab CLI Without MCP next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitLab CLI Without MCP compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitLab CLI Without MCP this skillzereight/gitlab-mcp2k—~787Automated safety check: PassMIT
MCP Integration for Pluginsanthropics/claude-plugins-official37k11 repos~3.1kAutomated safety check: PassApache-2.0
Cao MCP Appsawslabs/cli-agent-orchestrator1.4k—~1.9kAutomated safety check: PassApache-2.0
Building MCP Server On CloudflareCommandCodeAI/agent-skills132—~1.5kAutomated safety check: PassMIT
Nuxt Agent Ready Best Practicesvinayakkulkarni/nxui212—~2.4kAutomated safety check: PassMIT
Nv Onboard Dcr MCPnovuhq/novu40k—~1.8kAutomated safety check: PassCustom licence

Similar skills

  • MCP Integration for Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to bundle Model Context Protocol servers in a Claude Code plugin, covering config files, stdio, SSE, HTTP and WebSocket server types, and authentication.

    37k GitHub starsUsed in 11 repos~3.1k tokens
    Agent WorkflowsAuto-check passed
  • Cao MCP Apps

    awslabs/cli-agent-orchestrator

    Official

    Enable, operate, and extend CAO's MCP Apps surface — the host-rendered fleet dashboard visible inside MCP App hosts (Claude Desktop, ChatGPT, VS Code Copilot, Goose, Postman).

    1.4k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    132 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Nuxt agent-readiness guidelines for making a site operable by autonomous AI agents — not just cited by them.

    212 GitHub stars~2.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Onboard a new DCR OAuth MCP catalog entry with provider-doc vetting and curl probes.

    40k GitHub stars~1.8k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Agent Tools

    VectorSpaceLab/AREX-Skill

    A skill your agent uses when configuring LiteLLM for MCP tools, A2A agents, Claude Code/Cursor agent gateway traffic, MCP auth/OAuth, tool permissions, semantic filtering, or agent-specific proxy…

    328 GitHub stars~1.2k tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed

More from zereight/gitlab-mcp

All 24 skills in this repo
  • OMG Mode Canceller

    zereight/gitlab-mcp

    Detects which autonomous OMG mode is currently active - Autopilot, Ralph, Ultrawork, UltraQA, Team or Self-Improve - and shuts it down cleanly.

    2k GitHub starsUsed in 1 repo~690 tokens
    Auto-check passed
  • CCG Tri-Model Orchestration

    zereight/gitlab-mcp

    Runs a task through Codex and Gemini CLIs in parallel alongside Claude, then synthesizes the three outputs into one answer with agreements and conflicts called out.

    2k GitHub starsUsed in 1 repo~657 tokens
    Auto-check passed
  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    Auto-check passed
  • Remember Project Knowledge

    zereight/gitlab-mcp

    Sorts what you learned in a session into the right memory surface, filtering out ephemeral notes and duplicates before anything is stored.

    2k GitHub starsUsed in 1 repo~846 tokens
    Auto-check passed
  • Pre-Commit Security Scan

    zereight/gitlab-mcp

    Runs a fast security sweep of recent code changes before a commit or PR, checking for leaked secrets, vulnerable dependencies, unsafe input handling and auth gaps.

    2k GitHub starsUsed in 1 repo~859 tokens
    Auto-check: notes
  • Skill Inventory Stocktake

    zereight/gitlab-mcp

    Audits a project's skill directories for broken frontmatter, missing template sync and quality gaps, then produces a health report of what needs fixing.

    2k GitHub starsUsed in 1 repo~1k tokens
    Auto-check passed

Questions about GitLab CLI Without MCP

What does GitLab CLI Without MCP do?

Authenticates and runs zereight-mcp-gitlab as a plain command line tool to read GitLab merge requests, diffs, discussions, issues and pipelines when no MCP client is set up. The same zereight-mcp-gitlab binary that serves as an MCP server also works as a GitLab CLI: run a command and it prints the result and exits, with no MCP client involved. The agent first runs user whoami to check credentials, and depending on the result either proceeds, asks the user to authenticate, or tells them to reinstall the package if the command is missing.

When should I use GitLab CLI Without MCP?

GitLab CLI Without MCP fits situations like: reading a GitLab merge request, its diff or discussion threads without an MCP client; checking pipeline status or approval state on a merge request from the terminal; setting up CLI-only access to GitLab with a personal access token or OAuth.

How do I install GitLab CLI Without MCP in Claude Code?

Run `npx skills add zereight/gitlab-mcp --skill gl-cli -a claude-code`. Or copy the skill folder (skills/gl-cli in zereight/gitlab-mcp) into .claude/skills/gl-cli in your project. Claude Code loads it when a task matches its description.

How do I install GitLab CLI Without MCP in Codex?

Run `npx skills add zereight/gitlab-mcp --skill gl-cli -a codex`. Or copy the skill folder (skills/gl-cli in zereight/gitlab-mcp) into .agents/skills/gl-cli in your project. Codex loads it when a task matches its description.

Can I use GitLab CLI Without MCP in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add zereight/gitlab-mcp --skill gl-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gl-cli, .gemini/skills/gl-cli, .github/skills/gl-cli and .opencode/skills/gl-cli in your project.

What does GitLab CLI Without MCP need to run?

Going by SKILL.md and its folder, GitLab CLI Without MCP needs the command-line tools its instructions call (npm and git) and credentials named GITLAB_PERSONAL_ACCESS_TOKEN. Our summary lists: The @zereight/mcp-gitlab package installed globally; A GitLab personal access token or an OAuth application ID.

Does GitLab CLI Without MCP access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is GitLab CLI Without MCP safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does GitLab CLI Without MCP use?

GitLab CLI Without MCP is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitLab CLI Without MCP use?

About 787 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitLab CLI Without MCP?

Skills that share tags, products or a category with GitLab CLI Without MCP: MCP Integration for Plugins (anthropics/claude-plugins-official, 37k stars), Cao MCP Apps (awslabs/cli-agent-orchestrator, 1.4k stars), Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 132 stars) and Nuxt Agent Ready Best Practices (vinayakkulkarni/nxui, 212 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitLab CLI Without MCP?

zereight (a GitHub user) maintains it in zereight/gitlab-mcp, which has 2,027 GitHub stars. The repository holds 24 skills in this directory. The repository was last updated on October 6, 2026.

Source: zereight/gitlab-mcp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.