AgentStack
SKILL verified MIT Self-run

Gh Protect

skill-thettwe-nyann-gh-protect · by thettwe

>

No reviews yet
0 installs
12 views
0.0% view→install

Install

$ agentstack add skill-thettwe-nyann-gh-protect

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

Are you the author of Gh Protect? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

gh-protect

Standalone GitHub protection management. Wraps bin/gh-integration.sh in two modes: --check (read-only audit) and apply (write). Lets users manage branch protection, tag rulesets, signing requirements, and repo-level merge settings independently of bootstrap or doctor.

1. Pre-flight

Guard on gh:

command -v gh && gh auth status

If either fails, tell the user gh is required for this skill and stop. Unlike other skills that soft-skip, protection management has no useful fallback without gh.

2. Resolve profile

Load the active profile via bin/load-profile.sh (resolves preferences → CLAUDE.md markers → "default" fallback).

If the user names a specific profile, use that instead.

3. Audit first (always)

Run the read-only check regardless of whether the user asked to audit or apply — the delta informs what apply would change:

bin/gh-integration.sh --target  --profile  --check

Output conforms to schemas/protection-audit.schema.json. Show the user a summary table:

| Area | Expected | Actual | Drift | |---|---|---|---| | Branch protection (branches[]) | from profile | from GitHub API | critical / warn / ok | | Tag rulesets | .github.tag_protection_pattern | GitHub Rulesets API | critical / warn / ok | | CODEOWNERS gate | .github.require_code_owner_reviews | branch protection | critical / warn / ok | | Signing | .github.require_signed_commits/tags | branch protection + local git config | critical / warn / ok | | Repo settings | .github.allow_*_merge, delete_branch_on_merge | repo API | warn / ok | | Security signals | Dependabot, secret scanning, push protection, code scanning | repo API | info |

If everything is ok, report "protection matches profile" and stop (no apply needed).

4. Offer to apply (if drift found)

If any drift exists at critical or warn level, ask:

"Apply protection rules to match the profile? This will update branch protection via the GitHub API."

On confirmation:

bin/gh-integration.sh --target  --profile 

The apply mode never downgrades stricter remote rules — it only tightens. Relay this constraint so the user understands that loosening protection requires manual GitHub UI changes.

Output is a GhIntegrationResult JSON (schemas/gh-integration-result.schema.json). Report:

  • applied[] — rules that were created or updated.
  • noop[] — rules already at or above the expected level.
  • errors[] — rules that failed to apply (permission issues, etc.).

5. Report

After audit-only or audit+apply, end with:

  • Protection status per branch (protected / unprotected / partial).
  • Tag ruleset status.
  • Any errors[] that need manual attention.

When to hand off

  • "Check overall repo health" → doctor skill (includes protection

as one signal among many).

  • "Set up this repo from scratch" → bootstrap-project skill (applies

protection as part of the full pipeline).

  • "I changed my profile's GitHub settings" → re-run this skill to

apply the updated expectations.

  • "Loosen a protection rule" → explain that gh-integration.sh never

downgrades; the user must change the rule via the GitHub UI or API directly.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.