pipeline

A workflow for investigating failed GitLab CI/CD pipelines, which are automated jobs that build, test, or deploy code. It reads the relevant summary and failure details to identify the cause.

In plain words
What is it for?
Use it to analyse failed job logs, test reports, configuration errors, and child pipelines, then explain the cause and suggest fixes.
Why use it?
It focuses investigation on the failed jobs and their useful reports instead of making developers search through every pipeline log.

Command

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add commands/fprochazka/claude-code-plugins/pipeline
Clone the repo
git clone --depth 1 https://github.com/fprochazka/claude-code-plugins
Per session 9 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 509 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00009 $0.00509
Opus 5 $0.00005 $0.00254
Sonnet 5 $0.00002 $0.00102
Haiku 4.5 $0.00001 $0.00051

Measured 2d ago against content hash 8a5a9508ce3e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

pipeline scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/glab/commands/pipeline.md · 41 lines

What it actually says

Context

${CLAUDE_PLUGIN_ROOT}/scripts/fetch-mr-state.sh --pipeline

Your task

Analyze the MR pipeline state above, no implementation yet. Help triage any issues by analyzing the logs of any failed jobs and looking up the context and proposing fixes. If all jobs passed, report the pipeline status and note that no action is needed.

Reading the pipeline dump

The script already ran glab-pipeline inspect for you. Read the dump in this order and stop as soon as you have the cause:

  1. The pipeline summary file printed above — it names each failed job, its stage, and its failure reason, and it points at the file that explains it. Read it first, never the raw dump directory.
  2. job-logs/<failed-job>.log for a script or runtime failure — the tail carries the error. Read only the logs the summary names. Do not read the logs of jobs that passed.
  3. test-report.json for a test failure — it holds per-test results, which beats grepping a long trace.
  4. lint.json and merged.yml for a YAML, needs, or config error — they show what GitLab actually parsed.
  5. downstream/<bridge>-<id>.json for a failed child pipeline, then recurse with glab-pipeline inspect --pipeline-id <id>.

summary.json in the same directory holds the same summary as structured data. Use it when you want to filter with jq instead of reading prose.

Running glab-pipeline yourself

Invoke the glab-pipeline skill before you run the CLI directly. Run it again when the dump is stale or incomplete:

  • After a retry or a new push, to inspect the new pipeline.
  • With --with-merged-ci-config when an include: resolves differently on the source branch.
  • With --with-test-report when a test job failed but the report is missing.

Use glab ci retry <job-name> to retry a job. glab-pipeline inspects only, so it has no retry of its own.

$ARGUMENTS

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 41 lines · 9 tokens per session scan A 8a5a9508ce3e

Subscribe to this mod's changes

pipeline is a command published in the GitHub repository fprochazka/claude-code-plugins (11 stars, last pushed 4d ago), licensed MIT. It adds 9 tokens to every session and 509 once invoked, about $0.0000 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.