Install
$ agentstack add skill-thettwe-nyann-gh-protect ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
gh-protect
Standalone GitHub protection management. Wraps bin/gh-integration.sh in two modes: --check (read-only audit) and apply (write). Lets users manage branch protection, tag rulesets, signing requirements, and repo-level merge settings independently of bootstrap or doctor.
1. Pre-flight
Guard on gh:
command -v gh && gh auth status
If either fails, tell the user gh is required for this skill and stop. Unlike other skills that soft-skip, protection management has no useful fallback without gh.
2. Resolve profile
Load the active profile via bin/load-profile.sh (resolves preferences → CLAUDE.md markers → "default" fallback).
If the user names a specific profile, use that instead.
3. Audit first (always)
Run the read-only check regardless of whether the user asked to audit or apply — the delta informs what apply would change:
bin/gh-integration.sh --target --profile --check
Output conforms to schemas/protection-audit.schema.json. Show the user a summary table:
| Area | Expected | Actual | Drift | |---|---|---|---| | Branch protection (branches[]) | from profile | from GitHub API | critical / warn / ok | | Tag rulesets | .github.tag_protection_pattern | GitHub Rulesets API | critical / warn / ok | | CODEOWNERS gate | .github.require_code_owner_reviews | branch protection | critical / warn / ok | | Signing | .github.require_signed_commits/tags | branch protection + local git config | critical / warn / ok | | Repo settings | .github.allow_*_merge, delete_branch_on_merge | repo API | warn / ok | | Security signals | Dependabot, secret scanning, push protection, code scanning | repo API | info |
If everything is ok, report "protection matches profile" and stop (no apply needed).
4. Offer to apply (if drift found)
If any drift exists at critical or warn level, ask:
"Apply protection rules to match the profile? This will update branch protection via the GitHub API."
On confirmation:
bin/gh-integration.sh --target --profile
The apply mode never downgrades stricter remote rules — it only tightens. Relay this constraint so the user understands that loosening protection requires manual GitHub UI changes.
Output is a GhIntegrationResult JSON (schemas/gh-integration-result.schema.json). Report:
applied[]— rules that were created or updated.noop[]— rules already at or above the expected level.errors[]— rules that failed to apply (permission issues, etc.).
5. Report
After audit-only or audit+apply, end with:
- Protection status per branch (protected / unprotected / partial).
- Tag ruleset status.
- Any
errors[]that need manual attention.
When to hand off
- "Check overall repo health" →
doctorskill (includes protection
as one signal among many).
- "Set up this repo from scratch" →
bootstrap-projectskill (applies
protection as part of the full pipeline).
- "I changed my profile's GitHub settings" → re-run this skill to
apply the updated expectations.
- "Loosen a protection rule" → explain that
gh-integration.shnever
downgrades; the user must change the rule via the GitHub UI or API directly.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: thettwe
- Source: thettwe/nyann
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.