github-cli — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited github-cli (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Safety-first wrapper for GitHub CLI (gh). Every command is classified by risk level before execution.
gh apibrew install gh or see https://cli.github.comgh auth logingh --version (requires v2.86+)gh auth status — confirm repo, read:org scopes minimumEvery gh command falls into one of four risk tiers:
| Tier | Action Required | Examples |
|---|---|---|
| Safe | Execute immediately | gh pr list, gh issue view, gh repo view |
| Write | Inform user, then execute | gh pr create, gh issue create, gh release create |
| Destructive | AskUserQuestion BEFORE executing | gh pr merge, gh pr close, gh release delete |
| Forbidden | Multi-step validation, NEVER auto-confirm | gh repo delete, gh repo transfer, visibility changes |
See references/safety-rules.md for the full classification and confirmation templates.
Command received
→ Classify risk tier (see Quick Reference)
→ Safe? Execute immediately
→ Write? Inform user what will happen → execute
→ Destructive? AskUserQuestion with options → wait for answer → execute or cancel
→ Forbidden? Warn → require typed confirmation → final confirm → execute or cancel| Command | Description |
|---|---|
gh pr list | List pull requests |
gh pr view | View PR details |
gh pr checks | View CI status |
gh pr diff | View PR diff |
gh issue list | List issues |
gh issue view | View issue details |
gh repo view | View repo info |
gh repo list | List repos |
gh repo clone | Clone a repo |
gh release list | List releases |
gh release view | View release details |
gh run list | List workflow runs |
gh agent-task list / view | List/inspect Copilot coding-agent tasks (v2.80+) |
gh run view | View run details |
gh run view --log | View run logs |
gh workflow list | List workflows |
gh workflow view | View workflow details |
gh run download | Download workflow artifacts |
gh api (GET) | Read-only API calls |
gh auth status | Check auth |
gh browse | Open repo in browser |
gh status | Check your GitHub dashboard |
gh gist list | List your gists |
gh gist view | View gist details |
gh label list | List labels |
gh search repos | Search repos |
gh search issues | Search issues |
gh search prs | Search PRs |
gh search code | Search code |
| Command | Description |
|---|---|
gh pr create | Create PR |
gh agent-task create | Kick off a Copilot coding-agent session (opens PRs on your repo — inform user; v2.80+) |
gh skill install | Install an agent skill (gh skill is public preview, Apr 2026) |
gh pr edit | Edit PR metadata |
gh pr comment | Comment on PR |
gh pr review | Submit review |
gh pr ready | Mark PR as ready |
gh pr checkout | Check out a PR branch locally |
gh issue create | Create issue |
gh issue edit | Edit issue |
gh issue comment | Comment on issue |
gh issue reopen | Reopen a closed issue |
gh issue pin | Pin an issue |
gh issue unpin | Unpin an issue |
gh label create | Create label |
gh label edit | Edit label |
gh release create | Create release |
gh repo create | Create new repo |
gh repo edit | Edit repo settings (non-visibility) |
gh repo fork | Fork a repo |
gh repo rename | Rename a repository |
gh gist create | Create a new gist |
gh gist edit | Edit an existing gist |
gh run rerun | Re-run workflow |
gh workflow enable | Enable workflow |
gh workflow disable | Disable workflow |
gh workflow run | Manually trigger a workflow |
gh secret set | Set secret |
gh variable set | Set variable |
gh api -X POST/PUT/PATCH | Write API calls |
| Command | Description |
|---|---|
gh pr merge | Merge PR (irreversible in most workflows) |
gh pr close | Close PR |
gh issue close | Close issue |
gh issue delete | Delete issue (permanent) |
gh issue transfer | Transfer issue to another repo |
gh release delete | Delete release |
gh label delete | Delete label |
gh repo archive | Archive repo |
gh secret delete | Delete secret |
gh variable delete | Delete variable |
gh auth logout | Log out of GitHub CLI |
gh run cancel | Cancel running workflow |
gh api -X DELETE | Delete API calls |
| Command | Description |
|---|---|
gh repo delete | Delete repository (PERMANENT) |
gh repo transfer | Transfer repo ownership |
gh repo edit --visibility | Change repo visibility |
| Bulk destructive loops | Any loop running delete/close/merge |
# List open PRs
gh pr list
# Create PR (Write — inform user first)
gh pr create --title "feat: add auth" --body "$(cat <<'EOF'
## Summary
- Add JWT authentication middleware
## Test plan
- [ ] Unit tests pass
- [ ] Manual login flow verified
EOF
)"
# View PR with checks
gh pr view 42
gh pr checks 42
# Merge PR (Destructive — AskUserQuestion first)
gh pr merge 42 --squash --delete-branch# List issues with filters
gh issue list --label bug --assignee @me
gh issue list --state closed --limit 10
# Create issue (Write)
gh issue create --title "Bug: login fails" --body "Steps to reproduce..." --label bug
# View issue
gh issue view 123
# Close issue (Destructive — confirm first)
gh issue close 123 --reason completed# List releases
gh release list
# Create release (Write — inform user)
gh release create v1.2.0 --generate-notes --title "v1.2.0"
# Create release with assets
gh release create v1.2.0 ./dist/*.tar.gz --title "v1.2.0" --notes "Release notes here"
# Delete release (Destructive — confirm first)
gh release delete v1.2.0# List recent runs
gh run list --limit 10
# View specific run
gh run view 12345
# View logs for failed run
gh run view 12345 --log-failed
# Re-run failed jobs (Write)
gh run rerun 12345 --failed
# Cancel running workflow (Destructive — confirm)
gh run cancel 12345
# Manage secrets (Write for set, Destructive for delete)
gh secret set API_KEY --body "sk-..."
gh secret list# View repo info
gh repo view
# Create repo (Write)
gh repo create my-app --public --clone
# Clone
gh repo clone owner/repo
# Fork (Write)
gh repo fork owner/repo --clone
# Archive (Destructive — confirm first)
gh repo archive owner/repo# GET (Safe)
gh api repos/owner/repo/pulls
gh api repos/owner/repo/issues/123/comments
# POST (Write)
gh api repos/owner/repo/issues -f title="Bug" -f body="Description"
# DELETE (Destructive — confirm first)
gh api repos/owner/repo/issues/123/labels/bug -X DELETEgh evolves monthly. On any error: read it → gh help <command> → if still unclear, WebFetch https://cli.github.com/manual/gh_<command> (underscores join subcommands, e.g. gh_pr_merge) → adjust → re-run. Release notes: https://github.com/cli/cli/releases.
For Destructive operations, use AskUserQuestion with tailored options:
Question: "How should PR #42 'feat: add auth' be merged?"
Options:
- "Squash and merge" — Combine all commits into one
- "Create merge commit" — Preserve commit history
- "Rebase and merge" — Rebase onto base branch
- "Cancel" — Do not mergeQuestion: "Close PR #42 'feat: add auth'?"
Options:
- "Close only" — Close without deleting branch
- "Close and delete branch" — Close PR and remove source branch
- "Cancel" — Keep openQuestion: "Delete release v1.2.0?"
Options:
- "Delete release only" — Keep the git tag
- "Delete release and tag" — Remove both release and git tag
- "Cancel" — Keep releaseFor Forbidden operations, follow the triple-confirmation protocol in references/safety-rules.md.
| Error | Cause | Fix |
|---|---|---|
gh: command not found | Not installed | brew install gh |
authentication required | Not logged in | gh auth login |
HTTP 403 | Insufficient scopes | gh auth refresh -s scope |
HTTP 404 | Repo not found or no access | Check repo name and permissions |
HTTP 422 | Validation failed | Check required fields, branch exists |
HTTP 409 | Merge conflict | Resolve conflicts first |
HTTP 429 | Rate limited | Wait, or use --limit to reduce calls |
GraphQL: ... | API query error | Check field names and types |
| Flag | Description | ||
|---|---|---|---|
--json fields | Output specific JSON fields | ||
--jq expr | Filter JSON with jq expressions | ||
--template tmpl | Format output with Go templates | ||
-R owner/repo | Target a different repo | ||
--limit N | Limit results | ||
| `--state open\ | closed\ | all` | Filter by state |
--label name | Filter by label | ||
--assignee user | Filter by assignee | ||
--author user | Filter by author | ||
--web | Open in browser |
-i or --interactive flagscat if output may trigger a pager: gh pr list | catPairs with:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.