Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Github Cli

ASecurity

gh CLI patterns, JSON field discovery, PR check interpretation, label management, merge settings verification, CodeQL/GHAS gating.

5 stars
0 votes
0 copies
1 views
Added 10/4/2026
ai-agentsbashgitapisecurity

Works with

cliapi

Security Analysis

A100/100

Scanned 10/4/2026

$npx -y skills add juan294/cc-rpi --skill github-cli --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Github Cli?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Github Cli
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/juan294-github-cli/badge)](https://www.skillsdirectory.com/skills/juan294-github-cli)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: "github-cli"
description: "gh CLI patterns, JSON field discovery, PR check interpretation, label management, merge settings verification, CodeQL/GHAS gating."
---

# GitHub CLI

## JSON Field Discovery

Wrong -- guess field names:

```bash
gh pr checks 42 --json conclusion  # Unknown field
```

Right -- discover fields first:

```bash
gh pr checks --help
```

## PR Check Interpretation

Use the documented fields and preserve the command status:

```bash
gh pr checks 42 --json name,state,bucket,workflow
# Or watch existing checks to completion:
gh pr checks 42 --watch
```

Pending checks return exit **8**. Exit 1 can mean failed checks or another
command error; inspect output. `bucket` distinguishes `pass`, `fail`,
`pending`, `skipping`, and `cancel`. Do not discard a check merely because
its name is `review`; inspect its workflow and the repository's requirements.
An empty or incomplete check inventory is not evidence that required CI ran.
These commands inspect existing checks; they do not authorize PR creation.
See the [GitHub CLI manual](https://cli.github.com/manual/gh_pr_checks).

## Release vs PR Flags

Wrong -- --body is for pr/issue create, not release:

```bash
gh release create v1.0.0 --body "notes"
```

Right -- releases use --notes:

```bash
gh release create v1.0.0 --notes "notes"
```

## Label and Merge Settings

Wrong -- assume labels exist and merge method is allowed:

```bash
gh issue create --label "chore" --title "Fix"  # label not found
gh pr merge 42 --merge                         # method not allowed
```

Right -- check or create first:

```bash
gh label list && gh label create "chore" --color "ededed"
gh api repos/{owner}/{repo} --jq '.allow_squash_merge, .allow_merge_commit'
```

When creating multiple issues, create them sequentially, not as parallel
tool calls -- a batch of parallel `gh issue create` calls that all hit the
same missing label fail together instead of surfacing once.

## Deprecated Projects (Classic) API

Wrong -- an older `gh` version queries a removed field and errors:

```bash
gh issue view 42 --json projectCards  # Projects (classic) is deprecated
```

Right -- upgrade `gh` first:

```bash
brew upgrade gh
```

## Code Scanning Availability

Before adding a scanner, inspect repository visibility, the enabled security
product, and the caller's permissions:

```bash
gh api repos/{owner}/{repo} --jq '{visibility, security_and_analysis}'
gh api --include repos/{owner}/{repo}/code-scanning/alerts
```

A successful alerts request proves this caller can read that endpoint. A 403
can mean missing permissions, policy restrictions, rate limits, or disabled
code security; a 404 can hide a private resource. Neither means "enabled".
Inspect the HTTP status, response message, and token permissions together.
Code scanning is available for public repositories and eligible private or
internal repositories with GitHub Code Security enabled. Do not enable a paid
product or trigger a scanner without the owner's authorization. Read-only
inspection of existing alerts is allowed. See [GitHub's code-scanning API](https://docs.github.com/en/rest/code-scanning/code-scanning).

## Duplicate PR Prevention

Apply mutation recipes only within an authorized completed release workflow.
Working branches remain local; do not create feature PRs for implementation.

Wrong -- create PR when one already exists for this branch:

```bash
gh pr create --title "feat: thing"
```

Right -- check first, edit if exists:

```bash
gh pr list --head <branch> --base <base>
# Exists: gh pr edit <number>  |  New: gh pr create
```

## Identifier Discovery

Wrong -- fabricate repo names or issue numbers:

```bash
gh issue view 42 --repo owner/MyProject
```

Right -- discover identifiers:

```bash
gh repo list owner --json name --limit 50
gh issue list --search "bug in login"
```

Attribution

juan294juan294
View sourceSee grades on GitHubMore from juan294 →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698461 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →