github
GitHub via gh CLI: PRs, issues, reviews, repos, auth.
How do I install this agent skill?
npx skills add https://github.com/nousresearch/hermes-agent --skill githubIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
This skill provides comprehensive GitHub integration but recommends insecure practices, such as storing authentication tokens in plaintext on disk and embedding them in repository URLs. It also processes external data from GitHub issues and logs without explicit sanitization, which presents a surface for indirect prompt injection.
- Socketfail
1 alert: gptMalware
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
GitHub
Work GitHub end to end with the gh CLI (REST fallback where noted): auth,
issues, the PR lifecycle, issue-to-PR delivery, code review, and repo
management. This skill consolidates six former skills; each workflow lives
complete in its reference file — ALWAYS read the matching reference before
starting that workflow, the body below only routes.
Routing
| Task | Read first |
|---|---|
| Auth broken / new machine / token or SSH setup / gh login | references/auth.md |
| Create, triage, label, assign, close issues | references/issues.md |
| Branch, commit, open PR, watch CI, merge | references/pr-workflow.md |
| Carry an ISSUE to a verified PR (full delivery loop) | references/issue-to-pr.md |
| Review someone's PR: diffs, inline comments, verdict | references/code-review.md |
| Clone/create/fork repos, remotes, releases | references/repo-management.md |
Supporting assets: scripts/gh-env.sh + scripts/git-credential-token.py
(auth helpers), templates/ (PR bodies, bug report, feature request),
references/ci-troubleshooting.md, references/conventional-commits.md,
references/github-api-cheatsheet.md, references/review-output-template.md.
Core discipline (applies to every workflow)
- Preflight once per session:
gh auth status— if it fails, go toreferences/auth.mdbefore anything else. - Prefer
ghover raw REST; drop togh apionly for endpoints the porcelain lacks (the cheatsheet lists them). - Never report CI green without checking
gh pr checksyourself; never claim merged without verifyingstate,mergedAt. - Read full context before writing:
gh issue view --comments/gh pr view --comments— decisions live in threads, not titles. - Sweep for duplicates before creating anything:
gh pr list --search/gh issue list --search.
Verification
- The workflow's own reference file defines done for that task.
- Cross-cutting: every claim about remote state (CI, merge, release,
issue state) is backed by a fresh
ghread, never memory.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/nousresearch/hermes-agent/github">View github on skillZs</a>