Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/parendumou/nexora/gitlab_readnpx skills add ParendumOU/Nexora --skill gitlab_readgit clone --depth 1 https://github.com/ParendumOU/NexoraWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00439 |
| Opus 5 | $0.00000 | $0.00219 |
| Sonnet 5 | $0.00000 | $0.00088 |
| Haiku 4.5 | $0.00000 | $0.00044 |
Grade A, and why
gitlab_read scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
GitLab Read
Read access: projects, issues, MRs, files, pipelines, members.
Tool: gitlab_api
ALWAYS use gitlab_api — credentials auto-resolved. NEVER call http_request against gitlab.com/api/....
Common actions
current_user— verify authlist_projects— visible repos (scope: member/owned/starred/all)list_groups— accessible namespaceslist_subgroups— children of parent grouprepo_info— single project metadatalist_issues/list_mrs— per-projectread_file— file at reflist_branches/list_commits/list_pipelinessearch— global across projects/issues/MRs/commits/users/blobs
Legacy tools
gitlab_repo_info, gitlab_list_issues, gitlab_list_mrs, gitlab_read_file — back-compat only. Prefer gitlab_api → chain multiple actions in one response.
Requirements
PAT stored in Settings → Integrations → GitLab. Self-hosted: credential carries base_url.
PAT scope = human who issued it (not service account, not admin):
list_projects scope=member→ ONLY projects PAT owner is member of.list_groups→ ONLY groups owner belongs to.- Empty
[]= PAT genuinely has no membership. Do NOT retry with guessed names.
Anti-hallucination
Always use real API responses verbatim. Never invent project names, slugs, ids, namespaces, branches, paths, URLs, or "probable" repos. Inventory smaller than expected → say so, suggest checking PAT scope.
Example
[
{"name": "gitlab_api", "args": {"action": "current_user"}},
{"name": "gitlab_api", "args": {"action": "list_projects", "scope": "member", "visibility": "private", "max_pages": 10}}
]
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 45 lines · 0 tokens per session scan A 0035fb90d233
gitlab_read is a skill published in the GitHub repository ParendumOU/Nexora (19 stars, last pushed 1mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 439 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
html-preview
使用 Markdown html:preview 围栏输出轻量静态 HTML/CSS 可视化。当普通 Markdown 难以清晰表达数值对比、层级关系、流程、时间线、关键指标或布局示意,或用户明确要求可视化 HTML 预览时使用。询问 HTML 源码、教程示例或可复制代码时不要使用。.
deep-research
深度研究编排方法论:澄清范围、拆解规划、并行调度子智能体调研、对抗式核验、综合成带引用的结构化报告。当任务需要多来源、可追溯、需事实核查的深度研究时使用此技能。.
mysql reporter
生成 MySQL 查询报表并生成可视化图表。当用户需要查询 MySQL 数据库并以报表形式展示结果时使用此技能,包括:统计销售数据、分析用户行为、生成业务报表、查询业务指标等。.
knowledge-base
使用 Yuxi 知识库进行检索、打开文档、文档内定位和查看思维导图。当用户需要基于已配置知识库回答问题、核验资料或引用文档内容时使用此技能。.
background-task
Add or modify work that runs outside the request/response cycle — emails, document ingestion, webhooks, cleanups, scheduled jobs. Use when something is slow or fire-and-forget, or when adding a periodic/cron task. This project's queue is {{ cookiecutter.backgroundtasks }}.
agent-tool
Add a new tool/function the AI agent can call (e.g. look something up, hit an external API, perform an action). Use when extending the assistant's capabilities, wiring a new function into the agent, or when the model needs a new action. This project uses {{ cookiecutter.aiframework }}.