clab — security grade SAFE, quality 66/100

Security audit verdict: SAFE · quality 66/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by mberneti · Claude Skill · ★ 51

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is clab safe to install? View the security audit →

About clab

clab AI-powered GitLab MR code review as a Claude Code skill. Fetches the diff, runs lint rules, and posts inline comments — no external services, no Node.js. Can also analyze past MRs to generate project-specific review rules automatically. How it works Claude Code invokes Go binaries in sequence: Claude performs a semantic review on top of the lint output, then calls with the combined findings. Demo Installation Installs , , , and to . Custom install directory: bash CLABINSTALLDIR=/.local/bin curl -fs

Quick Facts

Stars51
Forks3
LanguageGo
CategoryClaude Skill
Quality Score65.8840419288312/100
Last Updated2026-05-25
Created2026-05-24
Platformsclaude-code, go
Est. Tokens~18k

Compatible Skills

These tools work well together with clab for enhanced workflows:

  • mcp-gitlab-server — semantic(0.28)+complementary+similar_pop+shared_platform (50%)

More Claude Skill Tools

Explore other popular claude skill tools:

View all Claude Skill tools →

Popular Go Agent Tools

Frequently Asked Questions

What is clab?

clab is Open source Claude skill for automated GitLab MR reviews. Configurable lint rules, semantic analysis, and inline comment posting for self-hosted GitLab instances.. It is categorized as a Claude Skill with 51 GitHub stars.

What programming language is clab written in?

clab is primarily written in Go.

How do I install or use clab?

You can find installation instructions and usage details in the clab GitHub repository at github.com/mberneti/clab. The project has 51 stars and 3 forks, indicating an active community.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Claude Skill tools