AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Github Triage

skill-raul-cgk-agent-skills-github-triage · by raul-cgk

Read-only routing of a scoped GitHub issue or pull-request queue. Use when a maintainer needs to know what is ready, needs refinement or owner input, or should be deferred, and when maintainer-orchestrator needs evidence-backed intake.

No reviews yet
0 installs
39 views
0.0% view→install

Install

$ agentstack add skill-raul-cgk-agent-skills-github-triage

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-raul-cgk-agent-skills-github-triage)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Github Triage? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

GitHub Triage

  • Use explicit issues, pull requests, filters, or repositories when supplied.
  • For direct invocation without explicit scope, use the current GitHub repository.
  • Require an explicit request before broadening across repositories.
  • Treat labels, assignment, milestones, and project status as signals, never readiness proof.
  • Remain read-only: do not comment, label, assign, close, merge, patch, change project state, or spawn agents.
  • Stop after routing. Do not implement work, perform the final code review, or decide landing.

Triage loop

Scope

  • Resolve scope in this order: explicit items or filters → explicit repositories → current repository.
  • Never broaden silently.
  • Inventory the requested scope before selecting items for deeper inspection.
  • Inspect every item when feasible; otherwise inspect the slice most likely to change routing.
  • Report exact coverage and anything skipped.

Understand

  • Read repository rules and the product or architecture sources they identify.
  • Read each surfaced item's body, material comments, and current GitHub state.
  • Inspect code, diff, CI, tests, history, or dependency evidence only as far as needed for a reliable route.
  • State the observable desired outcome, user or repository impact, owning surface, and important dependencies.
  • Separate issue or PR claims from evidence you verified.
  • Name material risk from blast radius, reversibility, contracts, data, security, concurrency, lifecycle, or compatibility.
  • Classify risk:
  • LOW — localized, reversible, no contract, data, security, or concurrency boundary.
  • MEDIUM — multiple callers or meaningful failure-path or operability risk.
  • HIGH — contract, data, migration, concurrency, lifecycle, compatibility, or broad blast radius.
  • CRITICAL — security boundary, irreversible data or infrastructure, or production-wide blast radius.
  • Stop before autoreview-level analysis unless correctness determines whether the item is actionable at all.

Test readiness

Route an item as ready only when all hold:

  • Outcome: the next action and observable completion condition are clear.
  • Decision completeness: a worker need not choose product or contract behavior.
  • Boundaries: owning surfaces and dependencies are identifiable and bounded.
  • Authority: the action fits repository delegation rules.
  • Proof: a credible verification path exists.
  • Risk: material failure surfaces are known well enough to name review lenses.

Without repository delegation rules, treat only reversible, behavior-preserving, verifiable work as ready. Route user-visible, contract, data, security, infrastructure, or irreversible changes to the owner.

Route

  • READY — passes the readiness test. Name the next action: IMPLEMENT, REVIEW, FIX, or PROVE.
  • REFINE — missing technical evidence or boundaries that an agent can obtain without an owner decision.
  • OWNER — needs product or contract choice, owner-only access, irreversible authority, or an explicit waiver.
  • DEFER — stale, duplicate, superseded, invalid, out of scope, or not worth acting on.

Do not use REFINE for evidence available through a cheap read-only check in the current pass. Use it when the investigation exceeds triage scope or needs dedicated work.

Credential rule:

  • Access required to understand or implement safely → OWNER.
  • Access required only for final proof, with an exact owner-run proof path → READY with a proof dependency.
  • No reliable proof path → OWNER.

Output contract

Use URL-first items in this order. Omit empty sections.

SCOPE
Repository/filter: 
Coverage: 
Skipped: 

READY
 — 
Action: IMPLEMENT | REVIEW | FIX | PROVE
Outcome: 
Impact: 
Basis: 
Boundaries: 
Risk: 
Proof: 

REFINE
 — 
Missing: 
Investigate: 

OWNER
 — 
Decision/access: 
Why owner: 

DEFER
 — 
Reason: 
  • Route code execution to the orchestrator; do not prescribe worker count or reviewer topology.
  • Do not include type, size, priority, author trust, or lifecycle fields unless the caller explicitly needs them.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.