AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Github

skill-mathews-tom-armory-github · by Mathews-Tom

GitHub CLI operations via `gh` for issues, PRs, Actions, releases, and REST/GraphQL API with `--json`/`--jq` parsing. Triggers on: "create an issue", "submit a PR", "check CI status", "why did CI fail", "merge a PR", or pasted GitHub URLs.

No reviews yet
0 installs
14 views
0.0% view→install

Install

$ agentstack add skill-mathews-tom-armory-github

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-mathews-tom-armory-github)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Github? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

GitHub

All GitHub operations use the gh CLI. Prefer --json with --jq for structured, parseable output. Use --repo owner/repo when not inside a git repository with a configured remote. Use --web to open any resource in the browser.

Prerequisites and Auth

Installation

| Platform | Command | | ------------- | --------------------------- | | macOS | brew install gh | | Debian/Ubuntu | sudo apt install gh | | Windows | winget install GitHub.cli |

Authentication

gh auth login           # interactive OAuth login
gh auth status          # check current auth and active account

Required OAuth Scopes

| Scope | Grants Access To | | ------------- | -------------------------------------------- | | repo | Private repos, issues, PRs, commits, status | | read:org | Org membership, team listing | | workflow | Trigger and manage GitHub Actions workflows | | gist | Create and manage gists | | delete_repo | Delete repositories (not granted by default) | | admin:org | Manage org settings, teams, members | | project | Read/write access to ProjectV2 boards |

Add missing scopes without re-authenticating from scratch:

gh auth refresh --scopes repo,read:org,workflow

Reference Routing

| User intent | Load | | --------------------------------------------------------------- | ------------------------------------ | | Create/list/view/edit/close issues, add comments | references/issues.md | | Create/list/view/review/merge/edit/close pull requests | references/pull-requests.md | | List runs, view logs, trigger/rerun/watch workflows, artifacts | references/ci-actions.md | | Create/fork/clone/view/edit/archive/delete repositories | references/repos.md | | Create/list/view/edit/upload/delete releases | references/releases.md | | Search repos, issues, PRs, code, commits | references/search.md | | Raw REST/GraphQL via gh api, pagination, rate limit | references/api.md | | GraphQL cost model, bulk queries, mutations, rate limits | references/graphql-queries.md | | Multi-step workflow recipes (PR lifecycle, CI triage, releases) | references/automation-workflows.md | | Create/list/view/edit/delete gists | references/gists.md | | List orgs, teams, members | references/orgs.md |

Workflow Pattern

  1. Identify user intent from the routing table above.
  2. Load the matching references/.md for command syntax and examples.
  3. Execute the gh command with --repo owner/repo and --json/--jq as needed.
  4. On error, consult the Error Handling table below.

Error Handling

| Error | Cause | Resolution | | ----------------------------- | ------------------------------------------------------------------------- | --------------------------------------------------------------------------------- | | HTTP 401 Unauthorized | Token expired or revoked | Run gh auth login to re-authenticate | | HTTP 403 Forbidden | Insufficient permissions or rate limited | Check gh auth status for scopes; check gh api rate_limit | | HTTP 404 Not Found | Repo does not exist, is private without repo scope, or resource deleted | Verify repo name; run gh auth refresh --scopes repo | | HTTP 422 Unprocessable Entity | Invalid payload — missing required field, validation error | Check request body fields match API schema | | HTTP 429 Too Many Requests | REST rate limit exceeded (5000 req/hr authenticated) | Wait for X-RateLimit-Reset timestamp; reduce request frequency | | GraphQL rate limit exceeded | Used more than 5000 points/hr | Reduce query complexity or wait; see references/graphql-queries.md | | "no git remotes found" | Running gh outside a git repo without --repo | Add --repo owner/repo to the command | | Insufficient OAuth scopes | Token lacks required scope for the operation | Run gh auth refresh --scopes scope1,scope2 | | Duplicate issue/PR title | Not a real error — GitHub allows duplicates, but check before creating | Search with gh issue list or gh pr list first | | Archived repo blocks writes | Repo is archived; all write operations fail | Unarchive with gh repo edit owner/repo --archived=false or use a different repo |

Enable debug logging to see raw HTTP requests and responses:

GH_DEBUG=api gh pr list --repo owner/repo

Calibration Rules

  1. Prefer --json over parsing text output. Text output formats are unstable across gh versions. Always use --json field1,field2 to get machine-readable output.
  2. Use --jq to minimize output before processing. Filter at the source rather than piping large JSON blobs to external tools. --jq runs server-side and reduces data transferred.
  3. Prefer higher-level commands over raw API. Use gh issue create instead of gh api repos/.../issues -X POST. High-level commands handle auth, pagination, and error formatting automatically.
  4. Use --repo consistently when outside a git directory. Never rely on implicit repo detection in scripts or CI environments. Always pass --repo owner/repo explicitly.
  5. Use GraphQL only for nested or bulk data. For single-resource fetches and mutations with simple payloads, REST is faster to write, easier to debug, and predictable under rate limits.

Limitations

  • Network required — all gh commands require internet access; no offline mode.
  • GraphQL point budget — 5000 points/hr for authenticated users. Complex queries with

high first/last values consume points faster. See references/graphql-queries.md.

  • Secrets are write-onlygh secret set works, but there is no gh secret get.

Secret values cannot be retrieved after creation.

  • Org admin operations — managing org settings, teams, and SAML requires the admin:org

scope, which is not granted by default.

  • Artifact retention — workflow artifacts are retained for 90 days by default. Expired

artifacts cannot be downloaded.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.