No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by mberneti · Claude Skill · ★ 51
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is clab safe to install? View the security audit →
clab AI-powered GitLab MR code review as a Claude Code skill. Fetches the diff, runs lint rules, and posts inline comments — no external services, no Node.js. Can also analyze past MRs to generate project-specific review rules automatically. How it works Claude Code invokes Go binaries in sequence: Claude performs a semantic review on top of the lint output, then calls with the combined findings. Demo Installation Installs , , , and to . Custom install directory: bash CLABINSTALLDIR=/.local/bin curl -fs
| Stars | 51 |
| Forks | 3 |
| Language | Go |
| Category | Claude Skill |
| Quality Score | 65.8840419288312/100 |
| Last Updated | 2026-05-25 |
| Created | 2026-05-24 |
| Platforms | claude-code, go |
| Est. Tokens | ~18k |
These tools work well together with clab for enhanced workflows:
Explore other popular claude skill tools:
clab is Open source Claude skill for automated GitLab MR reviews. Configurable lint rules, semantic analysis, and inline comment posting for self-hosted GitLab instances.. It is categorized as a Claude Skill with 51 GitHub stars.
clab is primarily written in Go.
You can find installation instructions and usage details in the clab GitHub repository at github.com/mberneti/clab. The project has 51 stars and 3 forks, indicating an active community.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: