CtrlK
BlogDocsLog inGet started
Tessl Logo

pantheon-ai/gitlab-ci-toolkit

Complete GitLab CI/CD toolkit with generation and validation capabilities for pipelines and configurations

97

Quality

97%

Does it follow best practices?

Impact

Pending

No eval scenarios have been run

SecuritybySnyk

Advisory

Suggest reviewing before use

Overview
Quality
Evals
Security
Files

summary.jsonvalidator/evals/

{
  "scenarios": [
    {
      "id": "scenario-0",
      "capability": "Security scan: detect hardcoded secrets, insecure script patterns, and SSL bypass",
      "feasible": true,
      "reason": "Agent reads .gitlab-ci.yml from task input and produces a security report — no pipeline execution required"
    },
    {
      "id": "scenario-1",
      "capability": "Syntax validation: stage references, job definitions, dependency graph (needs), deprecated keywords",
      "feasible": true,
      "reason": "Agent inspects static YAML structure and schema compliance — entirely text-based analysis"
    },
    {
      "id": "scenario-2",
      "capability": "Best practices: cache usage, artifact expiration, only/except migration to rules, image pinning",
      "feasible": true,
      "reason": "Agent reviews pipeline for best-practice patterns and produces actionable suggestions from static analysis"
    },
    {
      "id": "scenario-3",
      "capability": "Include file validation: detecting errors in locally included template files",
      "feasible": true,
      "reason": "Agent reads multiple YAML files provided inline and validates include targets — no external access required"
    },
    {
      "id": "scenario-4",
      "capability": "DAG optimization: identifying sequential pipeline bottlenecks and recommending needs-based parallelism",
      "feasible": true,
      "reason": "Agent analyzes job dependency structure from static YAML and recommends DAG improvements"
    }
  ]
}

tile.json