GitLab Code Review for Openclaw

An automated AI-powered agent that monitors GitLab commits and generates detailed security and quality reports on a schedule.

zhanghaiyu0511
v1.2.0
Mar 6, 2026
0
1.5k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install gitlab-code-review

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install gitlab-code-review using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is GitLab Code Review?

GitLab Code Review is a specialized automation skill designed to streamline the peer review process by leveraging artificial intelligence. By integrating seamlessly with Openclaw Skills, this agent monitors your GitLab repositories, identifies new code submissions, and performs a comprehensive analysis of every change. It bridges the gap between manual reviews and automated linting by providing context-aware feedback on complex architectural and logic issues.

The skill is built to be highly efficient, operating silently in the background and only triggering when there is actual work to be done. This ensures that developers receive timely, high-quality feedback directly in their preferred communication channels without needing to manually trigger scans or navigate complex CI/CD logs.

GitLab Code Review Use Cases

  • Continuous monitoring of development branches to ensure code quality standards.
  • Proactive security auditing to detect hardcoded secrets or injection vulnerabilities before they reach production.
  • Providing instant feedback to developers in remote teams via chat integrations like Feishu.
  • Reducing the cognitive load on senior engineers by filtering out trivial issues through AI-driven pre-reviews.

How GitLab Code Review Works

  1. The agent initializes by reading project configuration and credentials from a localized environment file.
  2. A specialized Python script polls the GitLab API to identify all commits made since the last successful audit.
  3. Discovered commits are stored as pending JSON objects in the local memory directory for systematic processing.
  4. The AI analyzes each commit across four critical dimensions: Security, Performance, Code Quality, and Testability.
  5. Detailed Markdown reports are generated for each commit, documenting specific issues and suggesting improvements.
  6. The agent pushes a summary and the full report file to the user via the Openclaw Skills messaging protocol and clears the pending queue.

GitLab Code Review Setup

First, ensure you have the necessary Python dependencies installed in your environment:

pip3 install requests python-dotenv

Configure your GitLab credentials and project details in workspace/.env:

GITLAB_URL=https://gitlab.example.com
GITLAB_TOKEN=your_personal_access_token
GITLAB_PROJECT=group/project
GITLAB_BRANCH=main

Finally, register the automated task using the Openclaw Skills cron management system:

openclaw cron add \
  --name "GitLab Code Review" \
  --cron "0 * * * *" \
  --stagger 5m \
  --channel your_channel_id \
  --to your_user_id \
  --message "Execute GitLab Code Review scheduled task"

GitLab Code Review Data Schema & Taxonomy

The skill maintains a structured data hierarchy to ensure consistency and prevent duplicate reviews:

File/Directory Purpose
memory/gitlab_review_state.json Persists the ID of the last reviewed commit to track progress.
memory/pending_review_*.json Stores commit metadata and diffs extracted during the fetch phase.
memory/code_review_*.md Contains the final AI-generated audit reports with line-specific suggestions.
scripts/fetch_commits.py The core logic for interfacing with the GitLab API and managing state.

GitLab Code Review Advanced Features

  • Intelligent Staggering: Uses a 5-minute stagger window to prevent network congestion during peak hours.
  • Silent Success Mode: To optimize resources, the skill performs a silent exit if no new commits are detected, avoiding unnecessary model calls.
  • Dual-Format Reporting: Delivers both a punchy, actionable summary for quick reading and a full Markdown document for deep dives.
  • Comprehensive Audit Dimensions: Evaluates code based on SQL injection risks, N+1 query problems, naming conventions, and dependency injection patterns.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*