gh-cli
An agent skill by trailofbits, from trailofbits/skills. Tags: api, automation, cli, github, web.
What it does
Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add trailofbits/skills --skill gh-cli
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/trailofbits/skills
cp -r skills/plugins/gh-cli/skills/gh-cli ~/.claude/skills/gh-cli
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- trailofbits/skills (all skills from this repository)
- Path
- plugins/gh-cli/skills/gh-cli/SKILL.md
- Branch
- main
- Collection
- gh-cli
- Updated
- 2026-09-19
Related skills
- running-release-tests — Run automated release testing (UI or API) via the AWS DevOps Agent using a pre-configured test profile.
- agent-web-search-setup — Sets up working web search on an agent whose model backend cannot run it.
- cli-developer — Use when building CLI tools, implementing argument parsing, or adding interactive prompts.
- csharp-developer — NET Core APIs, or Blazor web apps.
- dev-browser — Browser automation with persistent named pages via the dev-browser CLI.
- fastapi-expert — Use when building high-performance async Python APIs with FastAPI and Pydantic V2.