Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add vince-winkintel/gitlab-cli-skills --skill glab-configgit clone --depth 1 https://github.com/vince-winkintel/gitlab-cli-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/vince-winkintel/gitlab-cli-skills/glab-config)<a href="https://agentmods.dev/skills/vince-winkintel/gitlab-cli-skills/glab-config"><img src="https://agentmods.dev/badge/skills/vince-winkintel/gitlab-cli-skills/glab-config.svg" alt="Measured on agentmods" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00051 | $0.01927 |
| Opus 5 | $0.00026 | $0.00963 |
| Sonnet 5 | $0.00010 | $0.00385 |
| Haiku 4.5 | $0.00005 | $0.00193 |
Grade B, and why
glab-config scanned grade B with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Asks for rootmediumPrivilege escalation
A mod that escalates privileges can change anything on the machine, not only the project.
Keep these env files outside version control, restrict their permissions (for example `chmod 600`), be mindful of backup exposure, and use least-privilege bot/service-account tokens. How it starts
The opening of the file, as written. The whole thing — 169 lines — stays where its author put it; the contents beside it link to each section on GitHub.
glab config
Overview
Manage key/value strings.
Current respected settings:
- Global behavior: branch_prefix, browser, check_update, debug, display_hyperlinks,
duo_cli_auto_download, duo_cli_auto_run, editor, git_protocol, glab_pager,
glamour_style, host, no_prompt, notify_skill_updates, orbit_local_auto_download,
orbit_local_auto_run, remote_alias, show_whats_new, and telemetry.
- Per-host behavior: api_host, api_protocol, artifact_registry_domains, ca_cert,
client_cert, client_id, client_key, container_registry_domains, custom_headers,
job_token, proxy, skip_tls_verify, ssh_host, subfolder, token, and use_keyring.
- Accepted aliases include visual/glab_editor for editor, gitlab_host/gitlab_uri/gl_host
for host, prompt_disabled for no_prompt, and the full alias list in references/commands.md.
USAGE
glab config [command] [--flags]
COMMANDS
edit [--flags] Opens the glab configuration file.
get <key> [--flags] Prints the value of a given configuration key.
path [--flags] Print the location of the global configuration file.
set <key> <value> [--flags] Updates configuration with the value of a given key.
FLAGS
-g --global Use global config file.
-h --help Show help for this command.
Quick start
glab config --help
Per-host proxy configuration
Configure proxy for each GitLab host that requires a fixed proxy. This is useful when different GitLab instances (for example gitlab.com versus a self-hosted instance) require different proxy settings.
# Set the proxy for a specific host
glab config set proxy "http://proxy.example.com:8080" --host gitlab.mycompany.com
# Verify
glab config get proxy --host gitlab.mycompany.com
Precedence: A configured per-host proxy replaces environment-based proxy selection for that host. When it is unset, glab falls back to Go's standard HTTP_PROXY, HTTPS_PROXY, and NO_PROXY handling. proxy is host-scoped; use --host rather than writing a top-level value with --global.
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago Changed · -5 lines e163577e28f4
- 7d ago First seen · 174 lines · 51 tokens per session scan B 41617ebec634
glab-config is a skill published in the GitHub repository vince-winkintel/gitlab-cli-skills (47 stars, last pushed 5d ago), licensed MIT. It adds 51 tokens to every session and 1,927 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it B with 1 finding (asks for root). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
codex-autoresearch
Run autonomous, measurable experiments in a Git repository: change one hypothesis, verify a numeric metric, keep improvements, and revert failures. Use when the user wants Codex to keep iterating toward a numeric target in the foreground or as a detached background run. Do not use for ordinary one-shot coding…
changelog-composer
Generates structured changelogs and release notes from git history and PRs, classifying breaking changes, features, fixes, performance, docs. Triggers on: "generate changelog", "write release notes", "what changed since", "prepare release", "release notes for", "diff since tag".