cli-gh — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cli-gh (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Expert guidance for GitHub CLI (gh) operations and workflows. Use this skill for command-line GitHub operations including pull request management, issue tracking, repository operations, workflow automation, and codespace management.
Key capabilities:
CRITICAL: This skill NEVER uses destructive gh CLI operations.
This skill focuses exclusively on safe, read-only, or reversible GitHub operations. The following commands are PROHIBITED and must NEVER be used:
Permanently destructive commands:
gh repo delete - Repository deletiongh repo archive - Repository archivalgh release delete - Release deletiongh release delete-asset - Asset deletiongh run delete - Workflow run deletiongh cache delete - Cache deletiongh secret delete - Secret deletiongh variable delete - Variable deletiongh label delete - Label deletiongh ssh-key delete - SSH key deletion (can lock out users)gh gpg-key delete - GPG key deletiongh codespace delete - Codespace deletiongh extension remove - Extension removalgh gist delete - Gist deletionxargs with any destructive commandsrm -rf (except for temporary file cleanup)Allowed operations:
git status, git log, git diff)# Login to GitHub
gh auth login
# Login and copy OAuth code to clipboard automatically
gh auth login --clipboard
# Check authentication status
gh auth status
# Check auth status with JSON output
gh auth status --json
# Configure git to use gh as credential helper
gh auth setup-git# Create PR interactively
gh pr create
# Create PR with title and body
gh pr create --title "Add feature" --body "Description"
# Create PR to specific branch
gh pr create --base main --head feature-branch
# Create draft PR
gh pr create --draft
# Create PR from current branch
gh pr create --fill # Uses commit messages
# Create PR with Copilot Code Review
gh pr create --reviewer @copilot# List PRs
gh pr list
# List my PRs
gh pr list --author @me
# View PR details
gh pr view 123
# View PR in browser
gh pr view 123 --web
# View PR diff
gh pr diff 123
# View PR diff excluding specific files
gh pr diff 123 --exclude "*.lock"
# Check PR status
gh pr status# Checkout PR locally
gh pr checkout 123
# Review PR
gh pr review 123 --approve
gh pr review 123 --comment --body "Looks good!"
gh pr review 123 --request-changes --body "Please fix X"
# Request Copilot Code Review
gh pr edit 123 --add-reviewer @copilot
# Merge PR
gh pr merge 123
gh pr merge 123 --squash
gh pr merge 123 --rebase
gh pr merge 123 --merge
# Close PR
gh pr close 123
# Reopen PR
gh pr reopen 123
# Ready draft PR
gh pr ready 123
# Update PR branch with base branch
gh pr update-branch 123
# Revert a merged PR (creates a new revert PR)
gh pr revert 123# View PR checks
gh pr checks 123
# Watch PR checks
gh pr checks 123 --watch# Create issue interactively
gh issue create
# Create issue with title and body
gh issue create --title "Bug report" --body "Description"
# Use a Markdown issue template as interactive/editor starting body text
gh issue create --template "Bug Report"
# Create issue with labels
gh issue create --title "Bug" --label bug,critical
# Assign issue
gh issue create --title "Task" --assignee @me
# Set the issue type (GitHub.com and GHES 3.17+)
gh issue create --type Bug--template cannot be combined with --body or --body-file; use it with prompts, --editor, or --web. For YAML issue forms, fetch and render the form fields yourself for non-interactive automation, or finish in the browser.
# List issues
gh issue list
# List my issues
gh issue list --assignee @me
# List by label
gh issue list --label bug
# Filter by issue type
gh issue list --type Bug
# Advanced issue search
gh issue list --search "is:open label:bug sort:created-desc"
# View issue details
gh issue view 456
# View in browser
gh issue view 456 --web# Close issue
gh issue close 456
# Close as duplicate, linking to the original issue
gh issue close 123 --duplicate-of 456
# Reopen issue
gh issue reopen 456
# Edit issue
gh issue edit 456 --title "New title"
gh issue edit 456 --add-label bug
gh issue edit 456 --add-assignee @user
# Comment on issue
gh issue comment 456 --body "Update"
# Create branch to work on issue
gh issue develop 456 --checkoutIssue types and sub-issues require GitHub.com or GHES 3.17+; blocking relationships require GHES 3.19+.
# Set or remove the issue type
gh issue edit 456 --type Bug
gh issue edit 456 --remove-type
# Create a sub-issue under a parent
gh issue create --parent 100
# Organize existing issues into a parent/child hierarchy
gh issue edit 100 --add-sub-issue 123,124
gh issue edit 100 --remove-sub-issue 123
gh issue edit 123 --parent 100
gh issue edit 123 --remove-parent
# Track blocked-by / blocking relationships
gh issue create --blocked-by 200,201 --blocking 300
gh issue edit 123 --add-blocked-by 200 --add-blocking 300,301
gh issue edit 123 --remove-blocked-by 200 --remove-blocking 301When the user asks to list, view, create, edit, or comment on GitHub Discussions, see references/discussions.md. The gh discussion command set is in preview and subject to change.
Delegate work to the Copilot coding agent and track its sessions. The gh agent-task command set (aliases gh agent, gh agents) is in preview.
# Create an agent task on the current repository
gh agent-task create "Improve the performance of the data processing pipeline"
# List your most recent agent tasks
gh agent-task list
gh agent-task list --json id,name,state
# View an agent task session (by PR number, session ID, or URL)
gh agent-task view 123
gh agent-task view <session-id> --json state --jq '.state'Discover, install, and publish agent skills from GitHub repositories. The gh skill command set (alias gh skills) is in preview.
# Search for skills across GitHub
gh skill search terraform
# Preview a skill before installing
gh skill preview github/awesome-copilot documentation-writer
# Install a skill (default scope: project)
gh skill install github/awesome-copilot documentation-writer
gh skill install owner/repo skill-name --scope user --pin v1.2.0
# Include skills in hidden dirs (.claude/skills/, .agents/skills/, .github/skills/)
gh skill install owner/repo skill-name --allow-hidden-dirs
# List installed skills and update them
gh skill list
gh skill update --all
# Validate and publish your own skills
gh skill publish --dry-run# View repository
gh repo view
# View in browser
gh repo view --web
# Clone repository
gh repo clone owner/repo
# Clone without adding upstream remote
gh repo clone owner/repo --no-upstream
# Fork repository
gh repo fork owner/repo
# List repositories
gh repo list owner# Create repository
gh repo create my-repo --public
gh repo create my-repo --private
# Sync fork
gh repo sync owner/repo
# Set default repository
gh repo set-default
# Configure the squash-merge commit message default
gh repo edit --squash-merge-commit-message COMMIT_MESSAGESRead files and directories without cloning. The gh repo read-file and gh repo read-dir commands are in preview and subject to change.
# Read a file from the default branch (paged in a TTY, raw when piped)
gh repo read-file README.md --repo cli/cli
# Read from a specific branch, tag, or commit
gh repo read-file go.mod --ref v2.94.0 --repo cli/cli
# Write to disk instead of stdout (--clobber to overwrite)
gh repo read-file README.md --output ./README.md --clobber
# Refuse escape sequences by default; opt in for TTY/piped output
gh repo read-file script.sh --allow-escape-sequences
# List a directory (root when no path given)
gh repo read-dir script --repo cli/cli
# Inspect entries as JSON for scripting
gh repo read-dir docs --repo cli/cli --json name,path,type,sizeWhen the user asks to search GitHub repositories, issues, or pull requests, see references/search.md.
When the user asks to list, create, edit, or clone repository labels, see references/labels.md.
When the user asks to list, create, connect to, or manage files within GitHub Codespaces, see references/codespaces.md.
Open repositories, files, and resources in the browser.
# Open current repo in browser
gh browse
# Open specific file
gh browse src/main.go
# Open file at specific line
gh browse src/main.go:42
# Open blame view for a file
gh browse --blame src/main.go
# Open Actions tab
gh browse --actions
# Open specific branch
gh browse --branch featureWhen the user asks to create, list, view, or download GitHub releases, see references/releases.md.
When the user asks to create, list, view, or edit GitHub gists, see references/gists.md.
# Set default editor
gh config set editor vim
# Set default git protocol
gh config set git_protocol ssh
# View configuration
gh config list
# Set browser
gh config set browser firefoxCommon gh operations at a glance:
| Operation | Command | Common Flags |
|---|---|---|
| Create PR | gh pr create | --draft, --fill, --reviewer @copilot |
| List PRs | gh pr list | --author @me, --label, --search |
| View PR | gh pr view <number> | --web, --comments |
| Merge PR | gh pr merge <number> | --squash, --rebase, --delete-branch |
| Revert PR | gh pr revert <number> | --body |
| Create issue | gh issue create | --title, --body, --template, --type |
| List issues | gh issue list | --assignee @me, --label, --type |
| Close issue | gh issue close <number> | --duplicate-of, --reason |
| View issue | gh issue view <number> | --web, --comments |
| Link sub-issue | gh issue edit <number> | --parent, --add-sub-issue |
| Block issue | gh issue edit <number> | --add-blocked-by, --add-blocking |
| List discussions | gh discussion list | --answered, --sort, --json |
| Create agent task | gh agent-task create | --json (on list/view) |
| Install skill | gh skill install | --scope, --pin, --allow-hidden-dirs |
| Browse repo | gh browse | --blame, --actions, --branch |
| Clone repo | gh repo clone <repo> | --no-upstream |
| Fork repo | gh repo fork | --clone, --remote |
| View repo | gh repo view | --web |
| Read repo file | gh repo read-file <path> | --ref, --output, --clobber, --json |
| Read repo dir | gh repo read-dir [path] | --ref, --json |
| Create release | gh release create <tag> | --title, --notes, --draft |
| Verify release | gh release verify <tag> | --repo |
| Run workflow | gh workflow run <name> | --ref, --field |
| Watch run | gh run watch <id> | --exit-status |
| Search repos | gh search repos <query> | --language, --stars |
| Create label | gh label create <name> | --color, --description |
| Create codespace | gh codespace create | --repo, --branch |
For detailed patterns and advanced usage, see:
Practical automation scripts (see examples/ directory):
auto-pr-create.sh - Automated PR creation workflowissue-triage.sh - Bulk issue labeling and assignmentworkflow-monitor.sh - Watch and notify on workflow completionrelease-automation.sh - Complete release workflow automationWhen the user wants to use --json flags or needs the correct gh CLI JSON field names, see references/json-output.md.
--web flag to open items in browser for detailed view--author, --label, --state to narrow down lists efficiently--json flag to enable scriptable output for automationgh repo create --template to scaffold from template repositoriesgh pr merge --auto for PRs that pass checks~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.