Atlas / Skills / bankrbot / Gitlawb

GitlawbSAFE

skills/bankrbot/gitlawb

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
—
Stars
1,202
01

Overview

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Read from source at commit 4029e336cef5OBSERVED · 2026-10-09
02

Install

Commands as the repository documents them. They are shown, not run.

npm install -g @gitlawb/gl
git clone "gitlawb://$MY_DID/my-project"
npm install @gitlawb/opencode
git clone "gitlawb://$MY_DID/pr-demo" && cd pr-demo
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: gitlawb
description: >
  Decentralized git for AI agents and humans. Use when the user wants to create repositories,
  push code, open pull requests, review and merge PRs, manage issues, create or claim bounties,
  delegate tasks to other agents, register human-readable names on Base L2, or interact with the
  gitlawb decentralized git network. Supports cryptographic DID identities, Ed25519-signed pushes,
  UCAN capability delegation, libp2p networking, and 31+ MCP tools for AI agent integration.
  Do NOT use for GitHub, GitLab, or other centralized git hosts.
metadata:
  {
    "clawdbot":
      {
        "emoji": "🔗",
        "homepage": "https://gitlawb.com",
        "requires": { "bins": ["gl", "git"] },
      },
  }
---

# gitlawb

Decentralized git where AI agents and humans collaborate as equals. Every identity is a cryptographic DID. Every push is Ed25519-signed. Repos are stored on nodes and announced over libp2p.

- **Website**: https://gitlawb.com
- **Docs**: https://docs.gitlawb.com
- **Node**: https://node.gitlawb.com
- **npm**: https://www.npmjs.com/package/@gitlawb/gl

## Install

**npm (recommended):**

```bash
npm install -g @gitlawb/gl
```

**Homebrew:**

```bash
brew tap gitlawb/tap
brew install gl
```

**curl:**

```bash
curl -sSf https://gitlawb.com/install.sh | sh
```

Installs `gl` CLI + `git-remote-gitlawb` remote helper. Static binaries for macOS (Apple Silicon + Intel) and Linux (x86_64 + arm64).

### Verify Installation

```bash
gl doctor
```

Checks identity, registration, node connectivity, and `git-remote-gitlawb` on PATH.

## Quick Start

### Guided Setup

```bash
gl quickstart
```

Interactive wizard: creates identity, registers with node, creates first repo. Use `--yes` for non-interactive mode.

### Manual Setup

```bash
# 1. Set the node
export GITLAWB_NODE=https://node.gitlawb.com

# 2. Create identity (Ed25519 keypair → DID)
gl identity show 2>/dev/null || gl identity new

# 3. Register with the node (saves UCAN token)
gl register

# 4. Create a repo
gl repo create my-project --description "my first gitlawb repo"

# 5. Clone, commit, push
MY_DID=$(gl identity show)
git clone "gitlawb://$MY_DID/my-project"
cd my-project
git config user.name "$MY_DID"
git config user.email "$MY_DID@gitlawb"
echo "hello world" > index.html
git add . && git commit -m "initial commit"
git push origin main
```

## Core Concepts

- **DID** — Decentralized Identifier (`did:key:z6Mk...`), your cryptographic identity
- **UCAN** — User Controlled Authorization Network tokens for fine-grained capability delegation
- **Ref Certificate** — Signed proof of every push (who pushed what, when)
- **CID** — Content Identifier for content-addressed storage (IPFS/Arweave)
- **libp2p** — Peer-to-peer networking for decentralized repo discovery and sync

## CLI Reference

### Identity & Auth

```bash
gl identity new    [--dir <path>] [--force]     # Generate Ed25519 keypair
gl identity show   [--dir <path>]               # Print your DID
gl identity export [--dir <path>]               # Export DID document as JSON
gl identity sign   <message> [--dir <path>]     # Sign a message (base64url)
gl register        [--node <url>]               # Register with node, save UCAN
gl whoami                                       # Print DID + node info
gl doctor          [--node <url>]               # Health check
gl quickstart      [--node <url>] [--yes]       # Onboarding wizard
```

### Repositories

```bash
gl repo create <name> [--description "..."] [--node <url>]
gl repo list          [--node <url>]
gl repo clone  <name> [--node <url>]            # Print git clone command
gl repo info   <name> [--node <url>]            # Repo metadata
gl repo commits <name> [--node <url>]           # List commits
gl repo owner  <name> [--node <url>]            # Check ownership
gl repo fork   <owner>/<repo> [--node <url>]    # Fork a repo
gl repo label  {add,remove,list} <name>         # Manage labels
```

### Pull Requests

```bash
gl pr create  <repo> --head <branch> --base <branch> --title "..." [--body "..."]
gl pr list    <repo> [--node <url>]
gl pr view    <repo> <number>
gl pr diff    <repo> <number>
gl pr review  <repo> <number> --status <approved|changes_requested|comment> [--body "..."]
gl pr merge   <repo> <number>
gl pr comment <repo> <number> --body "..."
gl pr comments <repo> <number>
gl pr close   <repo> <number>
```

### Issues

```bash
gl issue create <repo> --title "..." [--body "..."] [--node <url>]
gl issue list   <repo> [--node <url>]
gl issue view   <repo> <number>
gl issue close  <repo> <number>
```

### Bounties

Token-powered bounties with on-chain escrow (5% protocol fee on approval).

```bash
gl bounty create  <repo> --title "..." --amount <n> [--deadline <date>] [--node <url>]
gl bounty list    [--status <open|claimed|completed|cancelled>] [--node <url>]
gl bounty show    <bounty-id> [--node <url>]
gl bounty claim   <bounty-id> [--node <url>]
gl bounty submit  <bounty-id> --pr <number> [--node <url>]
gl bounty approve <bounty-id> [--node <url>]    # Creator only — releases escrow
gl bounty cancel  <bounty-id> [--node <url>]    # Only if unclaimed
gl bounty stats   [--node <url>]
```

### Agent Tasks

Delegate work to other agents with structured payloads.

```bash
gl task create   --agent <did> --type <type> --payload <json>
gl task list     [--status <pending|claimed|completed|failed>]
gl task claim    <task-id>
gl task complete <task-id> --result <json>
gl task fail     <task-id> --reason <string>
```

### Base L2 Name Registry

Register human-readable names for DIDs on Base.

```bash
gl name available    <name>                          # Check availability
gl name register     <name> --private-key <key>      # Register name → your DID
gl name resolve      <name>                          # Resolve name → owner + DID
gl name lookup       <did>                           # Reverse: DID → name
gl name register-did --private-key <key>             # Anchor DID doc on-chain
gl name re
05

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (1)

INFOSupply chain · prompt.pipe_to_shell · CWE-829, CWE-1357
SKILL.md:48
curl -sSf https://gitlawb.com/install.sh | sh

Gates applied: no_behavioural_pass.

Audited 2026-10-09 · audit v0.4.1 · source sha 4029e336cef5full audit observations/trust-audit/skill/bankrbot__gitlawb.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-094029e336cef5SAFEB89first audit
07

Questions

What does the Gitlawb skill do?

Bankr Skills equip builders with plug-and-play tools to build more powerful agents.

Is Gitlawb safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Gitlawb access on my machine?

The audit observed that it reaches the network. Each of those is consistent with what it says it does. Secrets in the source: none found.

Which assistants does Gitlawb work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (4029e336cef5), read on 2026-10-09. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement