Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Github Mention Safety

ASecurity

Prevent tagging wrong GitHub users by always resolving usernames from git log or team membership before @-mentioning anyone in GitHub comments, PRs, or issues.

2 stars
0 votes
0 copies
0 views
Added 9/27/2026
documentationgobashgit

Works with

mcp

Security Analysis

A100/100

Scanned 9/27/2026

$npx -y skills add gethamster/skills --skill github-mention-safety --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Mention Safety?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Github Mention Safety
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/gethamster-github-mention-safety/badge)](https://www.skillsdirectory.com/skills/gethamster-github-mention-safety)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: github-mention-safety
description: "Prevent tagging wrong GitHub users by always resolving usernames from git log or team membership before @-mentioning anyone in GitHub comments, PRs, or issues."
version: "1.0.0"
---

# GitHub Mention Safety

## Goal

Never tag a GitHub user who is not a verified member of the team. Searching GitHub by name returns arbitrary public users who share a name — do not use search results as a source of truth for usernames.

## Hard Rules

1. **Never use `mcp__github__search_users` to derive a username for @-mention.** Search results match arbitrary public accounts by name — the top result is not necessarily a team member.
2. **Always resolve a contributor's GitHub username from git history** before mentioning them:

```bash
git log --all --format='%ae %an' | sort -u | grep -i <name>
```

   The noreply email format `<id>+<login>@users.noreply.github.com` gives the exact login.

3. **If git history has no noreply email**, fall back to `mcp__github__get_team_members` to enumerate actual org members, then match by name.
4. **If neither source confirms the login**, do not @-mention the person by username. Reference them by name only (e.g. "Edwin Chow (chowed)") or omit the mention entirely.

## Lookup Protocol (run before every @-mention)

```bash
# Step 1: Check git log for noreply email (most reliable)
git log --all --format='%ae %an' | sort -u | grep -i "<name>"
# Pattern: <id>+<login>@users.noreply.github.com  →  login is the GitHub handle

# Step 2: If not found, list org team members
# mcp__github__get_team_members({ org: "gethamster", team_slug: "<team>" })

# Step 3: Only @-mention if login is confirmed by one of the above
```

## Examples

```bash
# ✅ CORRECT — username confirmed from git noreply email
git log --all --format='%ae' | grep -i edwin
# → 29315749+chowed@users.noreply.github.com
# → safe to mention @chowed

# ❌ WRONG — username from GitHub user search
mcp__github__search_users({ query: "edwin hamster" })
# → returns EdwinTannn (unrelated public user)
# → do NOT mention this person
```

## If a Wrong Mention Was Already Posted

1. Immediately post a correction comment on the same PR/issue.
2. Explicitly apologize to the incorrectly tagged person.
3. Post a corrected mention using the verified username.

Attribution

gethamstergethamster
View sourceSee grades on GitHubMore from gethamster →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Context Fundamentals

Understand the components, mechanics, and constraints of context in agent systems. Use when designing agent architectures, debugging context-related failures, or optimizing context usage.

179001 votes

Architecture Diagram Creator

Create comprehensive HTML architecture diagrams with data flows, business context, and system architecture.

6661 votes

release-notes

Draft release notes and changelog entries from git history or merged PRs between two refs (tags/SHAs/branches), including breaking changes, migrations, and upgrade steps. Use when the user asks for release notes, changelog updates, or a GitHub Release draft.

1301 votes

docs-style-guide

Documentation style guide enforcer by @planetabhi. Applies and reviews the writing style guide when authoring or editing product documentation and tutorials. Use to check prose for voice, tense, word choice, inclusive language, formatting, code block, UI, Markdown, and number/date conventions.

11 votes

Docx

Use this skill whenever the user wants to create, read, edit, or manipulate Word documents (.docx files) or Word templates (.dotx files). Triggers include: any mention of 'Word doc', 'word document', '.docx', '.dotx', or requests to produce professional documents with formatting like tables of contents, headings, page numbers, or letterheads. Also use when extracting or reorganizing content from .docx or .dotx files, inserting or replacing images in documents, performing find-and-replace in W...

1798860 votes
View all in documentation →