Borrowing it
Nothing to install: this file belongs to theimaginaryfoundation/what-iff. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/theimaginaryfoundation/what-iff/main/.agents/skills/gh-pr/SKILL.mdgit clone --depth 1 https://github.com/theimaginaryfoundation/what-iffWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/theimaginaryfoundation/what-iff/gh-pr)<a href="https://agentmods.dev/skills/theimaginaryfoundation/what-iff/gh-pr"><img src="https://agentmods.dev/badge/skills/theimaginaryfoundation/what-iff/gh-pr/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/theimaginaryfoundation/what-iff/gh-pr"><img src="https://agentmods.dev/badge/skills/theimaginaryfoundation/what-iff/gh-pr.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00114 | $0.00693 |
| Opus 5 | $0.00057 | $0.00347 |
| Sonnet 5 | $0.00023 | $0.00139 |
| Haiku 4.5 | $0.00011 | $0.00069 |
Grade A, and why
gh-pr scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 78 lines — stays where its author put it; the contents beside it link to each section on GitHub.
File a GitHub pull request (public repo only)
Everything here is world-readable forever. No internal hostnames, customer
names, private-repo paths, Jira keys, Notion links, or session URLs in the
title or body — and no Generated with/Claude-Session style attribution.
1. Guard
REPO=$(gh repo view --json nameWithOwner -q .nameWithOwner)
[ "$REPO" = theimaginaryfoundation/what-iff ] || { echo "not the public repo ($REPO); stop"; exit 1; }
BRANCH=$(git branch --show-current)
[ "$BRANCH" != main ] || { echo "on main; create a feature branch first"; exit 1; }
case "$BRANCH" in *claude*) echo "branch name contains 'claude': $BRANCH"; exit 1;; esac
2. Dedupe
gh pr list --head "$BRANCH" --json number,url,state
If one is already open for this branch, report its URL instead of filing a second one.
3. Push and file
git push -u origin "$BRANCH"
Body sections must match the template headings exactly (## Summary,
## Test plan, ## Checklist) — same headings render the same and keep the
diff against the template minimal for reviewers. Fill every checklist item
you actually verified with [x]; leave the rest [ ], never delete them.
gh pr create -t "<summary, ≤72 chars, no trailing period>" -F - <<'BODY'
## Summary
- <what changed, in 1-3 bullets>
## Test plan
- [x] `make pre-commit`
- [ ] Frontend lint/test/build
- [x] Manually verified: <what you actually did>
## Checklist
- [x] No credentials, personal exports, generated local state, or production config committed
- [x] Public defaults still work without hosted services
- [ ] Updated architecture docs (only if this touches system boundaries)
- [ ] Regenerated the e2e SDK (only if `openapi.yaml` changed)
BODY
Report the URL gh prints. Only add -a @me, -l, --base, or -d
(draft) if asked.
4. Fix in place
If the description turns out wrong or incomplete after further review,
gh pr edit <N> -t/-F the original — never leave it standing and add a
"correction" comment.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- yesterday First seen · 78 lines · 114 tokens per session scan A ef8ab57f7b2d
gh-pr is a skill published in the GitHub repository theimaginaryfoundation/what-iff (15 stars, last pushed today), licensed Apache-2.0. It adds 114 tokens to every session and 693 once invoked, about $0.0006 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-09.
Other skills, from other repositories
prowler-commit
Creates professional git commits following conventional-commits format. Trigger: When creating commits, after completing code changes, when user asks to commit.
gh-auth-isolation
Safely manage multiple GitHub identities (EMU + personal) in agent workflows.
comet-github
A routing guide for Comet-related GitHub work. It directs requests about pull requests, issues, CI failures, ideas, and fixes to the appropriate review or implementation process.
github-skill
Work with GitHub via the gh CLI — clone repositories, create/list/merge pull requests, create/list issues, and run any other gh command (API calls, workflow runs, releases, repo administration). List operations return parsed JSON.
re0-merge
Review and land an external contribution the way this suite does: gate it against the thesis, land it with the author's credit intact, complete a new skill rather than merging it raw, then approve, credit, and explain before closing. Use when reviewing a pull request, as any collaborator or maintainer, not only the…
nvca-chart-release
Release NVCA Operator chart changes from the native monorepo source to the vendored Helm chart. Use when updating the vendored NVCA Operator chart, changing NVCA image refs, publishing helm-nvca-operator, or validating the chart against a self-managed control plane.