Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add fprochazka/claude-code-plugins --skill glabgit clone --depth 1 https://github.com/fprochazka/claude-code-pluginsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/fprochazka/claude-code-plugins/glab)<a href="https://agentmods.dev/skills/fprochazka/claude-code-plugins/glab"><img src="https://agentmods.dev/badge/skills/fprochazka/claude-code-plugins/glab.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00068 | $0.03248 |
| Opus 5 | $0.00034 | $0.01624 |
| Sonnet 5 | $0.00014 | $0.00650 |
| Haiku 4.5 | $0.00007 | $0.00325 |
Grade A, and why
glab scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 272 lines — stays where its author put it; the contents beside it link to each section on GitHub.
glab - GitLab CLI
Command-line interface for GitLab. Binary name: glab.
Repository Context
glab auto-detects the GitLab project from the git remote in the current directory. Override with --repo (-R):
glab mr list # auto-detected from git remote
glab mr list -R group/project # explicit project
glab mr list -R group/namespace/project
Identifying MRs
MR commands accept an MR IID number, a branch name, or nothing (current branch):
glab mr view 123 # by MR IID
glab mr view feature-x # by branch name
glab mr view # current branch's MR
Files for tool arguments
For any glab argument longer than a few words (MR descriptions, comments, job logs), put the content in a file and pass it via "$(cat <path>)" instead of inlining. Edits stay cheap, and the Write tool diff shows the user exactly what changed between revisions.
- If the content already exists as a file on disk, use it directly — do not copy it to
/tmpfirst. - When generating new content, write it to
/tmp/<unique-slug>.mdincluding the MR number, branch name, or job name (e.g.,/tmp/mr-desc-123.md,/tmp/glab-job-build-123.log). Never use generic names like/tmp/mr-description.md— they collide across MRs. - Reuse the same file for the same MR/entity across edits.
Creating a Merge Request
glab mr create --fill --fill-commit-body --yes -b main --draft -a user1 --reviewer user2 -l bug
| Flag | Short | Description |
|---|---|---|
--title |
-t |
MR title |
--description |
-d |
Description ("-" opens editor) |
--fill |
-f |
Use commit info, auto-push branch |
--fill-commit-body |
Include all commit bodies (with --fill) |
|
--draft |
Create as draft | |
--assignee |
-a |
Assign by username (comma-separated or repeated) |
--reviewer |
Request review by username | |
--label |
-l |
Add labels |
--milestone |
-m |
Assign milestone |
--target-branch |
-b |
Target branch |
--source-branch |
-s |
Source branch (default: current) |
--push |
Push branch before creating | |
--remove-source-branch |
Remove source branch on merge | |
--squash-before-merge |
Squash commits on merge | |
--related-issue |
-i |
Link to issue IID |
--copy-issue-labels |
Copy labels from linked issue | |
--yes |
-y |
Skip confirmation prompt |
--web |
-w |
Continue in browser |
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 272 lines · 68 tokens per session scan A c3982bbfbeea
glab is a skill published in the GitHub repository fprochazka/claude-code-plugins (13 stars, last pushed yesterday), licensed MIT. It adds 68 tokens to every session and 3,248 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
codex-autoresearch
Run autonomous, measurable experiments in a Git repository: change one hypothesis, verify a numeric metric, keep improvements, and revert failures. Use when the user wants Codex to keep iterating toward a numeric target in the foreground or as a detached background run. Do not use for ordinary one-shot coding…
changelog-composer
Generates structured changelogs and release notes from git history and PRs, classifying breaking changes, features, fixes, performance, docs. Triggers on: "generate changelog", "write release notes", "what changed since", "prepare release", "release notes for", "diff since tag".