Agent Skills
› trailofbits/skills
› gh-cli
gh-cli
GitHub强制使用 gh CLI 进行 GitHub 交互,替代未认证的 curl 请求。适用于处理仓库、PR、Issue 及私有库访问,确保认证与速率限制合规。
Trigger Scenarios
需要访问 GitHub 私有仓库或 API
准备对 GitHub 使用 curl 或未认证抓取
Install
npx skills add trailofbits/skills --skill gh-cli -g -y
SKILL.md
Frontmatter
{
"name": "gh-cli",
"description": "Enforces authenticated gh CLI workflows over unauthenticated curl\/WebFetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues."
}
gh-cli
When to Use
- Working with GitHub repositories, pull requests, issues, releases, or raw file URLs.
- You need authenticated access to private repositories or higher API rate limits.
- You are about to use
curl,wget, or unauthenticated web fetches against GitHub.
When NOT to Use
- The target is not GitHub.
- Plain local git operations already solve the task.
Guidance
Prefer the authenticated gh CLI over raw HTTP fetches for GitHub content. In particular:
- Prefer
gh repo view,gh pr view,gh pr list,gh issue view, andgh apiover unauthenticatedcurlorwget. - Prefer cloning a repository and reading files locally over fetching
raw.githubusercontent.comblobs directly. - Avoid using GitHub API
/contents/endpoints as a substitute for cloning and reading repository files.
Examples:
gh repo view owner/repo
gh pr view 123 --repo owner/repo
gh api repos/owner/repo/pulls
For the hook implementation, see:
plugins/gh-cli/README.mdplugins/gh-cli/hooks/
Version History
- 9b28133 Current 2026-08-20 09:17


