gh-aw: Skill for Claude Code

.github/skills/ssl/SKILL.md

ssl-skill-normalizer is a skill for Claude Code, Codex from github/gh-aw. It costs 30 tokens per session (2,251 once invoked), scanned A, original, MIT.

A tool for converting skill instructions written in Markdown into structured JSON with scheduling, structural, and logical information.

In plain words
What is it for?
It helps extract fields such as a skill's purpose, when it should run, its inputs and outputs, and its internal steps.
Why use it?
It makes free-form instructions easier for agents to search, understand, and assess.

Skill for Claude CodeCodex ✓ vendor

Written for no agent in particular: nothing here depends on one.

This is github/gh-aw's own configuration. It tells Claude Code and Codex how to work on gh-aw itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything gh-aw configures →

About the project

GitHub Agentic Workflows is a GitHub CLI extension that lets developers define AI-assisted repository automation in Markdown and run it through GitHub Actions. It is intended for tasks requiring interpretation or reasoning, such as issue triage, pull-request review, CI investigation, documentation maintenance, and dependency analysis. The catalogue entries provide skills and agents for working with these workflows.

github/gh-aw · 5,109 stars · on GitHub · gh.io

Reuse

Borrowing it

Nothing to install: this file belongs to github/gh-aw. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/github/gh-aw/main/.github/skills/ssl/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/github/gh-aw

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for ssl-skill-normalizer

README.md
[![agentmods](https://agentmods.dev/badge/skills/github/gh-aw/ssl.svg)](https://agentmods.dev/skills/github/gh-aw/ssl)
Your own site
<a href="https://agentmods.dev/skills/github/gh-aw/ssl"><img src="https://agentmods.dev/badge/skills/github/gh-aw/ssl.svg" alt="Measured on agentmods" height="20"></a>
Per session 30 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,251 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00030 $0.02251
Opus 5 $0.00015 $0.01125
Sonnet 5 $0.00006 $0.00450
Haiku 4.5 $0.00003 $0.00225

Measured 3d ago against content hash dffc2c929e02, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-07, from the pricing page.

Security

Grade A, and why

ssl-skill-normalizer scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/skills/ssl/SKILL.md · 289 lines

How it starts

The opening of the file, as written. The whole thing — 289 lines — stays where its author put it; the contents beside it link to each section on GitHub.

SSL Skill Normalizer

Purpose

This skill converts markdown-based skill artifacts into a structured Scheduling-Structural-Logical (SSL) representation as introduced in:

Liang et al., "From Skill Text to Skill Structure: The Scheduling-Structural-Logical Representation for Agent Skills", arXiv:2604.24026 (2026).

SSL addresses the core limitation of free-form skill text: it is human-readable but hard for agents to reason over, discover, and audit. By mapping each skill into three complementary layers, SSL makes skills searchable (improved MRR 0.573 → 0.707 in the paper) and risk-assessable (improved macro F1 0.744 → 0.787).


The Three SSL Layers

The representation is grounded in Schank & Abelson's theories of Memory Organization Packets (MOPs), Script Theory, and Conceptual Dependency. Each layer captures a different dimension of skill knowledge:

Layer 1 — Scheduling (When / Who)

Answers: When should this skill be invoked? By whom, given which inputs and outputs?

Fields extracted:

  • id — stable lowercase identifier
  • name — human-readable skill name
  • goal — one-sentence purpose
  • intent_signature — typed function signature (fn($input) -> $output)
  • inputs$-prefixed named input bindings
  • outputs$-prefixed named output bindings
  • dependencies — explicit runtime tool or library requirements
  • control_flow_features — e.g. sequential, conditional, loop
  • entry_scene — ID of the first scene to execute
  • subscene_refs — IDs of any nested/delegated scenes

Layer 2 — Structural (How / Order)

Answers: What are the macro-level execution stages and how do they connect?

Each scene is a named execution stage with:

  • id — unique within the skill
  • type — one of the restricted scene-type enum (see below)
  • goal — what the scene accomplishes
  • entry_condition — precondition for entering the scene
  • exit_condition — postcondition that must hold on exit
  • next_scene_rules — conditional transitions to the next scene ID, END_SUCCESS, or END_FAIL
  • inputs / outputs$-prefixed bindings consumed and produced
  • entry_logic_step — ID of the first logic step in this scene

Read the full file on GitHub · 289 lines

Files

What ships with it

1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 3d ago First seen · 289 lines · 30 tokens per session scan A dffc2c929e02

Subscribe to this mod's changes

ssl-skill-normalizer is a skill published in the GitHub repository github/gh-aw (5,109 stars, last pushed today), licensed MIT. It adds 30 tokens to every session and 2,251 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

c-github

Interact with GitHub using the gh CLI and jq. Manage PRs, issues, repositories, and Actions workflows. Make raw API calls with gh api for anything not covered by built-in commands.

daxaur/openpaw · 48 tokens

watch-pr

Watch a GitHub pull request for CI status, reviews, comments, merge conflicts, and terminal states using the gh-watch extension. Use when the user wants to monitor a PR, wait for CI, or track PR progress.

justincampbell/gh-watch · 48 tokens

watch-tag

Watch a GitHub repository for new tags using the gh-watch extension. Use when the user wants to be notified when a tag is created, when a release is cut, or when a tag that includes a specific commit appears (e.g. "tell me when my merge ships in a release").

justincampbell/gh-watch · 62 tokens

watch-branch

Watch a GitHub branch for new commits using the gh-watch extension. Use when the user wants to be notified when new commits are pushed to a branch, monitor main for merges, or track branch activity.

justincampbell/gh-watch · 45 tokens

watch-commit

Watch a GitHub commit for CI status changes using the gh-watch extension. Use when the user wants to monitor a commit's CI checks, wait for a build to finish, or track CI progress on a specific SHA.

justincampbell/gh-watch · 48 tokens

update-architecture-docs

Generate or update the architecture documentation in docs/content/architecture/. Use on "update architecture docs", "generate architecture documentation", "regenerate architecture docs", or after any structural change to the codebase.

AlexSkrypnyk/scaffold · 46 tokens