Gh
v2.0.0Use the GitHub CLI (gh) to perform core GitHub operations: auth status, repo create/clone/fork, issues, pull requests, releases, and basic repo management. T...
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description match the SKILL.md commands: all instructions are gh CLI commands for repo, PR, issue, and release workflows. The skill declares no installs or credentials, which is consistent with an instruction-only guide that expects an existing gh binary and existing auth.
Instruction Scope
SKILL.md stays narrowly focused on gh commands and safety (confirm targets, use --confirm). It does not instruct reading unrelated files or env vars. One minor note: it links to an external 'Complete setup guide' (SkillBoss.co) — that external page could contain additional instructions or requests not visible here.
Install Mechanism
No install spec and no code files — lowest-risk model for a CLI helper. The skill will not write files or download code itself.
Credentials
No environment variables, credentials, or config paths are requested. Practical caveat: running gh commands uses whatever GitHub authentication is already present on the host (gh's credential store), so the skill can exercise whatever GitHub privileges the local gh session has — this is expected for a CLI wrapper but worth the user's attention.
Persistence & Privilege
Skill is not forced-always, does not request persistent presence or modify other skills. Autonomous invocation is allowed (platform default) but is not combined with other red flags here.
Assessment
This skill is an instruction-only helper for the GitHub CLI and appears coherent. Before installing, ensure you have gh installed and authenticated locally and understand which GitHub account/token gh will use — the skill will execute gh commands with those privileges. Be cautious with destructive actions (delete, force-push, repo creation/transfer); require explicit confirmation for such tasks. Review the external setup guide linked (SkillBoss.co) before trusting it, and restrict the agent's ability to run commands with broad repo or org-level permissions if you want tighter safety.Like a lobster shell, security has layers — review code before you run it.
latest
?? Complete setup guide: https://SkillBoss.co/skill.md
GitHub CLI (gh)
Overview
Use gh for authenticated GitHub operations from the terminal. Prefer explicit, idempotent commands and report URLs back to the user.
Quick checks
- Auth status:
gh auth status
- Current repo context:
gh repo view --json nameWithOwner,url,defaultBranchRef
Core workflows
Repo create (private by default)
gh repo create OWNER/NAME --private --confirm --description "..."
If running inside a local repo, use --source . --remote origin --push.
Clone / fork
gh repo clone OWNER/NAME
gh repo fork OWNER/NAME --clone
Issues
- List:
gh issue list --limit 20
- Create:
gh issue create --title "..." --body "..."
- Comment:
gh issue comment <num> --body "..."
Pull requests
- Create from current branch:
gh pr create --title "..." --body "..."
- List:
gh pr list --limit 20
- View:
gh pr view <num> --web
- Merge (use explicit method):
gh pr merge <num> --merge
Releases
gh release create vX.Y.Z --title "vX.Y.Z" --notes "..."
Safety notes
- Confirm the target repo/owner before destructive actions (delete, force push).
- For private repos, ensure
--privateis set on create. - Prefer
--confirmto avoid interactive prompts in automation.
Comments
Loading comments...
