github-cli

A guide to using GitHub CLI, the command-line tool for working with GitHub repositories, pull requests, releases, issues, labels, and checks.

In plain words
What is it for?
Use it to inspect pull-request checks, discover available fields, create releases or issues, manage labels, and check allowed merge settings.
Why use it?
It helps avoid incorrect flags, unknown JSON fields, misleading check results, missing labels, and unsupported merge methods.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/juan294/cc-rpi/github-cli
Any agent
npx skills add juan294/cc-rpi --skill github-cli
Clone the repo
git clone --depth 1 https://github.com/juan294/cc-rpi

Made for: Claude Code, Codex.

Per session 28 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 783 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00028 $0.00783
Opus 5 $0.00014 $0.00392
Sonnet 5 $0.00006 $0.00157
Haiku 4.5 $0.00003 $0.00078

Measured yesterday against content hash df092250fbd9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

github-cli scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

templates/skills/github-cli/SKILL.md · 134 lines

How it starts

The opening of the file, as written. The whole thing — 134 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GitHub CLI

JSON Field Discovery

Wrong -- guess field names:

gh pr checks 42 --json conclusion  # Unknown field

Right -- discover fields first:

gh pr checks 42 --json 2>&1 | head -5

PR Check Interpretation

Wrong -- exit code 0 means passed, raw output is readable:

gh pr checks 42  # exit 0 but checks still pending; "review: fail" looks like CI

Right -- use structured JSON, filter review, or --watch:

gh pr checks 42 --json name,state,conclusion | jq '.[] | select(.name != "review")'
gh pr checks 42 --watch

Release vs PR Flags

Wrong -- --body is for pr/issue create, not release:

gh release create v1.0.0 --body "notes"

Right -- releases use --notes:

gh release create v1.0.0 --notes "notes"

Label and Merge Settings

Wrong -- assume labels exist and merge method is allowed:

gh issue create --label "chore" --title "Fix"  # label not found
gh pr merge 42 --merge                         # method not allowed

Right -- check or create first:

gh label list && gh label create "chore" --color "ededed"
gh api repos/{owner}/{repo} --jq '.allow_squash_merge, .allow_merge_commit'

When creating multiple issues, create them sequentially, not as parallel tool calls -- a batch of parallel gh issue create calls that all hit the same missing label fail together instead of surfacing once.

Deprecated Projects (Classic) API

Wrong -- an older gh version queries a removed field and errors:

gh issue view 42 --json projectCards  # Projects (classic) is deprecated

Right -- upgrade gh first:

brew upgrade gh

CodeQL Requires GHAS

Wrong -- add a code-scanning workflow without checking GHAS is enabled:

# .github/workflows/codeql.yml added blindly -- fails CI on every push

Right -- confirm GHAS is enabled before adding the workflow:

gh api repos/{owner}/{repo}/code-scanning/alerts  # non-403 = GHAS enabled

Read the full file on GitHub · 134 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 134 lines · 28 tokens per session scan A df092250fbd9

Subscribe to this mod's changes

github-cli is a skill published in the GitHub repository juan294/cc-rpi (5 stars, last pushed 12d ago), licensed MIT. It adds 28 tokens to every session and 783 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

claude-md-review

Audit a CLAUDE.md file for the patterns that actually degrade Claude Code's output — vagueness, unnamed files, stale facts, and bloat. Use when asked to review, audit, improve, shrink, or fix a CLAUDE.md, and when a project's results feel inconsistent or Claude keeps rediscovering the same context.

wesammustafa/Claude-Code-Everything-You-Need-to-Know · 69 tokens

best-practices

Searchable knowledge base of 152+ programming best practices across 30+ languages and frameworks. BM25-powered search over curated resources from industry leaders (Google, Airbnb, Uber, Mozilla, Shopify, OWASP).

dereknguyen269/programing-best-practices · 0 tokens

common-session-retrospective

Analyze conversation corrections to detect skill gaps and prepare targeted skill-library maintenance tasks. Use after any session with user corrections, rework, or retrospective requests. After finding correction loops, also load +common/common-learning-log to persist mistake entries to AGENTSLEARNING.md.

HoangNguyen0403/agent-skills-standard · 59 tokens

common-workflow-writing

Rules for writing concise, token-efficient workflow and skill files. Prevents over-building that requires costly optimization passes. Use when creating or editing workflow files, SKILL.md files, or new skill definitions.

HoangNguyen0403/agent-skills-standard · 45 tokens

JavaScript Tooling

Development tools, linting, and testing for JavaScript projects.

HoangNguyen0403/agent-skills-standard · 18 tokens

common-ui-design

Design distinctive, production-grade frontend UI with bold aesthetic choices. Use when building web components, pages, interfaces, dashboards, or applications in any framework (React, Next.js, Angular, Vue, HTML/CSS).

HoangNguyen0403/agent-skills-standard · 47 tokens