github-issue-agent

github-issue-agent is a skill for Claude Code, Codex from richfrem/agent-plugins-skills. It costs 80 tokens per session (1,366 once invoked), scanned A, original, MIT.

A GitHub Issues assistant for recording lasting repository bugs, development obstacles, and architectural improvements with supporting evidence.

In plain words
What is it for?
Use it to search, create, comment on, and validate GitHub Issues related to repository friction and technical debt.
Why use it?
It reduces duplicate or poorly documented issues and checks submissions for secrets, valid issue categories, and adequate evidence before changes are made.

Skill for Claude CodeCodex

Part of the dev-utils plugin — 17 skills, 2 agents shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/richfrem/agent-plugins-skills/github-issue-agent
Any agent
npx skills add richfrem/agent-plugins-skills --skill github-issue-agent
Clone the repo
git clone --depth 1 https://github.com/richfrem/agent-plugins-skills

Made for: Claude Code, Codex.

Or install dev-utils, the plugin that ships this one along with the rest of its 17 skills, 2 agents.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for github-issue-agent

README.md
[![agentmods](https://agentmods.dev/badge/skills/richfrem/agent-plugins-skills/github-issue-agent.svg)](https://agentmods.dev/skills/richfrem/agent-plugins-skills/github-issue-agent)
Your own site
<a href="https://agentmods.dev/skills/richfrem/agent-plugins-skills/github-issue-agent"><img src="https://agentmods.dev/badge/skills/richfrem/agent-plugins-skills/github-issue-agent.svg" alt="Measured on agentmods" height="20"></a>
Per session 80 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,366 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00080 $0.01366
Opus 5 $0.00040 $0.00683
Sonnet 5 $0.00016 $0.00273
Haiku 4.5 $0.00008 $0.00137

Measured yesterday against content hash 3ff0e92947ad, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

github-issue-agent scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

The scan reads SKILL.md. This mod also ships 15 executable files (scripts/body_validator.py, scripts/friction_cluster_agent.py, scripts/gh_issue_close.py, …), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/dev-utils/skills/github-issue-agent/SKILL.md · 101 lines

How it starts

The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.

GitHub Issue Agent (github-issue-agent)

Routing Directive: USE ONLY for durable repository bugs, execution friction (T1-T3), map debt, and architectural improvements. DO NOT USE for temporary intra-session checklists (use task-agent instead).

The github-issue-agent skill provides a safe, standardized interface for querying, searching, creating, commenting on, and validating GitHub Issues stemming from agent execution friction, map debt, bugs, and system improvements.


Dry-Run Default Execution Contract

[!IMPORTANT] Safety First: By default, all issue-modifying operations (issue creation, commenting, label edits) execute in dry-run / payload-generation mode (execute=False). No live mutation occurs unless execute=True is explicitly passed and all safety gates pass.

Before any GitHub issue is created or updated, the request passes through three mandatory security and quality gates:

  1. Secret Redaction Gate (redaction_gate.py): Scans titles and bodies for tokens, API keys, private keys, or credentials. Blocks execution if detected.
  2. Taxonomy Validation Gate (gh_issue_taxonomy_validate.py): Enforces issue-taxonomy.json constraints. Requires type:*, tier:*, source:*, risk:*, AND location (area:* OR plugin:*).
  3. Evidence Quality Body Validation Gate (body_validator.py): Requires standard structured markdown sections (## Summary, ## Observed Behavior, ## Expected Behavior, ## Evidence, ## Impact).

Operation Catalog

1. create-friction-issue

Scaffolds and submits (or outputs payload for) a friction issue resulting from agent execution friction or tool failure.

  • Helper Script: plugins/dev-utils/skills/github-issue-agent/scripts/gh_issue_create.py
  • Default Labels Required: type:friction, tier:1-friction (or tier:2-structural / tier:3-architecture), source:agent, risk:low (or appropriate risk level), plus location (area:* or plugin:*).
  • Input Parameters:
    • title: Short, clear summary of root-cause friction.
    • body: Markdown content conforming to required sections.
    • labels: List of taxonomy labels matching issue-taxonomy.json.
    • execute: Boolean (False for dry-run payload generation, True for live creation via gh).

Read the full file on GitHub · 101 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 101 lines · 80 tokens per session scan A 3ff0e92947ad

Subscribe to this mod's changes

github-issue-agent is a skill published in the GitHub repository richfrem/agent-plugins-skills (6 stars, last pushed yesterday), licensed MIT. It adds 80 tokens to every session and 1,366 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

kapso-whatsapp

How to interact with Kapso WhatsApp from the swarm — read inbound webhook payloads (text AND media), fetch message history, send free-form messages within the 24h session window (and template messages outside it), mark-as-read, show the typing indicator, send reactions, download media, verify webhook signatures, and…

desplega-ai/agent-swarm · 156 tokens

composio

Use Composio from Agent Swarm through the agent-swarm x composio CLI route, the swarmx MCP tool, or a registered ctx.api.composio script connection. Trigger when a task needs connected third-party app tools such as Gmail, Google Calendar, Google Docs, Google Drive, GitHub, Slack, Notion, or HubSpot through Tool Router…

desplega-ai/agent-swarm · 128 tokens

attio-interaction

Generic Attio CRM REST API v2 recipes for querying records, upserting companies/people/deals, writing notes/tasks/comments, managing lists, and handling webhooks.

desplega-ai/agent-swarm · 39 tokens

swarm-scripts

Bulk, repeat, fan-out, or data-heavy work: write and run swarm scripts (inline script-run, named script-upsert, durable launch-script-run). Covers the script-vs-tool rubric, the authoring contract (args first, ctx second), the seed catalog, connections and secrets, dbquery, and exposing a script as an API.

desplega-ai/agent-swarm · 82 tokens

user-management

How to manage the user registry — creating users for new Slack/GitHub/GitLab/Linear identities, managing aliases, resolving users across platforms. Use when a new human interacts with the swarm or when user identity needs updating.

desplega-ai/agent-swarm · 49 tokens

scheduled-task-resilience

Guardrails for polling, scheduled jobs, and long-running external operations. Use whenever a task waits on CI, builds, deploys, browser jobs, or another asynchronous API so work survives heartbeat checks without duplicate delivery.

desplega-ai/agent-swarm · 48 tokens