# Github Cli

> Apply when using the gh CLI to manage pull requests, issues, releases, or CI workflows on GitHub.

- **Type:** Skill
- **Install:** `agentstack add skill-sordi-ai-skill-everything-github-cli`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [sordi-ai](https://agentstack.voostack.com/s/sordi-ai)
- **Installs:** 0
- **Category:** [Developer Tools](https://agentstack.voostack.com/c/developer-tools)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [sordi-ai](https://github.com/sordi-ai)
- **Source:** https://github.com/sordi-ai/skill-everything/tree/main/skills/github-cli

## Install

```sh
agentstack add skill-sordi-ai-skill-everything-github-cli
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# Sub-Skill: GitHub CLI (`gh`) Conventions

**Purpose:** Consistent, auditable use of the `gh` CLI for PRs, issues, releases, and CI — preventing gate bypasses and silent failures.

---

## Rules

### Authentication & Scopes

1. **Check auth scope before scripting.** Before running `gh` in CI or scripts, always verify the required scopes are granted with `gh auth status`; missing scopes produce silent 404s rather than auth errors.
2. **Use token env var in CI.** Always pass `GH_TOKEN` (or `GITHUB_TOKEN`) via environment variable in CI pipelines; never hard-code tokens or use `gh auth login --with-token` interactively in automated contexts.

### Pull Requests

3. **Include all required labels on PR creation.** Always pass `--label` for every gate-required label when running `gh pr create`; omitting a label silently bypasses automated approval gates. Reference: ERR-2026-023
4. **Set reviewer on creation.** Always use `--reviewer ` when creating PRs that require CODEOWNERS approval; adding reviewers after creation delays the review clock.
5. **Open as draft when work is incomplete.** Use `gh pr create --draft` for PRs not yet ready for review; never open a ready-for-review PR on a branch with failing CI.
6. **Link issues explicitly.** Always include `--body "Closes #"` or `--body "Fixes #"` so GitHub auto-closes the linked issue on merge; never rely on branch name alone for issue linkage.

### Issues

7. **Assign and label on creation.** Use `gh issue create --assignee @me --label ` rather than creating bare issues and editing them in a second step; unassigned, unlabelled issues fall out of triage queues.
8. **Use JSON output for scripting.** Prefer `gh issue list --json number,title,labels` over parsing human-readable output; the `--json` flag is stable across `gh` versions, plain text is not.

### CI / Workflows

9. **Trigger runs explicitly when needed.** Use `gh workflow run  --ref ` to trigger a workflow rather than pushing an empty commit; empty commits pollute history.
10. **Watch run status in scripts.** After triggering a workflow, use `gh run watch ` or poll `gh run view  --json conclusion` rather than sleeping for a fixed duration.

### Releases & API

11. **Create releases from tags, not branches.** Always run `gh release create  --generate-notes` after pushing the tag; never target a branch directly, as branch-based releases produce non-reproducible artifacts.
12. **Use `gh api` for endpoints not covered by subcommands.** Prefer `gh api repos/{owner}/{repo}/pulls --jq '.[].number'` over raw `curl` with manual auth headers; `gh api` inherits the active auth context automatically.
13. **Define aliases for repeated commands.** Use `gh alias set` to capture long flag combinations used more than twice in a project; aliases are stored in `~/.config/gh/config.yml` and are portable across machines via dotfiles.

---

## See also

- `skills/git-conventions/SKILL.md`
- `skills/error-log/SKILL.md`

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [sordi-ai](https://github.com/sordi-ai)
- **Source:** [sordi-ai/skill-everything](https://github.com/sordi-ai/skill-everything)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** yes
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** no
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-sordi-ai-skill-everything-github-cli
- Seller: https://agentstack.voostack.com/s/sordi-ai
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
