Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add nasrulhazim/claude --skill gh-workflowgit clone --depth 1 https://github.com/nasrulhazim/claudeWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/nasrulhazim/claude/gh-workflow)<a href="https://agentmods.dev/skills/nasrulhazim/claude/gh-workflow"><img src="https://agentmods.dev/badge/skills/nasrulhazim/claude/gh-workflow/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/nasrulhazim/claude/gh-workflow"><img src="https://agentmods.dev/badge/skills/nasrulhazim/claude/gh-workflow.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 4 findings, up to high
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- high Privilege Escalation · line 780 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- high Privilege Escalation · line 783 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- high Privilege Escalation · line 784 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
- high Privilege Escalation · line 789 Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.Fix: Remove references to credential paths. Use environment variables or secrets managers. For docs, use placeholder paths (e.g., /path/to/config). Never load .env or token files in production code paths.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00248 | $0.14970 |
| Opus 5 | $0.00124 | $0.07485 |
| Sonnet 5 | $0.00050 | $0.02994 |
| Haiku 4.5 | $0.00025 | $0.01497 |
Grade A, and why
gh-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 1,817 lines — stays where its author put it; the contents beside it link to each section on GitHub.
GitHub CLI Workflow
Automate GitHub operations — from issue tracking to release management — using the gh CLI. Assumes gh auth login has been completed.
Command Reference
| Command | Description |
|---|---|
/gh issue |
Create, list, search, triage, and close issues |
/gh pr |
Create PRs, request reviews, check status, merge |
/gh actions |
List, trigger, watch, and debug workflow runs |
/gh repo |
Create, clone, fork repos; manage settings and visibility |
/gh release |
Create releases with assets, manage downloads |
/gh labels |
Scaffold and sync label sets across repositories |
/gh secrets |
Manage repository and environment secrets and variables |
/gh project |
Create and manage GitHub Projects — boards, custom fields, views, multi-repo tracking |
/gh report |
Generate repository and project reports in HTML, JSON, or Markdown format |
/gh api |
Raw GitHub API calls for advanced operations |
1. /gh issue — Issue Management
Create, list, search, and triage GitHub issues.
Create an Issue
gh issue create \
--title "Bug: login fails with SSO" \
--body "$(cat <<'EOF'
## Description
Login fails when using SSO provider.
## Steps to Reproduce
1. Click "Login with SSO"
2. Complete SSO flow
3. Redirected back with 500 error
## Expected Behaviour
User should be logged in and redirected to dashboard.
## Environment
- Laravel 12.x
- PHP 8.4
- Production
EOF
)" \
--label "bug,priority:high" \
--assignee "@me"
List and Filter Issues
# List open issues assigned to me
gh issue list --assignee "@me" --state open
# Search issues with filters
gh issue list --label "bug" --state open --limit 50
# Search across repos with query
gh search issues "login SSO" --repo owner/repo --state open
# JSON output for scripting
gh issue list --json number,title,labels,assignees --jq '.[] | "\(.number) \(.title)"'
Triage Workflow
# Add labels to an issue
gh issue edit 123 --add-label "priority:high,bug"
# Assign an issue
gh issue edit 123 --add-assignee "username"
# Add to a milestone
gh issue edit 123 --milestone "v2.0"
# Add a comment
gh issue comment 123 --body "Investigating — likely related to #120"
# Close with reason
gh issue close 123 --reason "completed" --comment "Fixed in #125"
What ships with it
7 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 1,817 lines · 248 tokens per session scan A 43b549eccdc5
gh-workflow is a skill published in the GitHub repository nasrulhazim/claude (22 stars, last pushed 6d ago), licensed MIT. It adds 248 tokens to every session and 14,970 once invoked, about $0.0012 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
mcore-split-pr
Split a PR into multiple PRs to reduce the number of required CODEOWNERS reviewer groups.
shiplog
Recap of everything shipped since the last run - cross-repo PRs, security fixes, star deltas, and X traction, synthesized into a digest article and a ready-to-post shiplog in your voice.
llxprt-issue-workflow
Use this skill when asked to address, fix, or work on a GitHub issue in the llxprt-code repository. Covers the complete issue lifecycle - branch setup, gh CLI usage, test-first planning, subagent delegation and review loops, the full verification cycle (including the stepfun-37 smoke test), open code review (ocr), PR…
cyrus-setup-repository
Add one or more Git repositories to Cyrus configuration so it can process issues from those repos.
github-sync
Bidirectional synchronization of epics and tasks with GitHub issues, labels, and relationships.
github-notification-triage
Triage GitHub notifications and issue/PR queues.