bundled-skills/github-automation/SKILL.md
Operate GitHub issues, pull requests, branches, checks, workflows, and permissions through Rube MCP. Use when GitHub work must be queried or changed programmatically with repository-policy safeguards.
npx skillsauth add FrancoStino/opencode-skills-antigravity github-automationInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Use Composio's GitHub toolkit through Rube MCP while preserving repository policy, exact revision identity, and branch protection.
Use for programmatic GitHub issue, pull-request, branch, Actions, deployment, collaborator, or protection tasks when Rube MCP is available. Prefer the native gh workflow or a repository-specific maintainer command when local repository policy requires it.
RUBE_SEARCH_TOOLS is available.RUBE_MANAGE_CONNECTIONS with toolkit github and complete OAuth only if the connection is not active.owner/repo; do not rely on a similarly named repository.Never request, print, or persist GitHub credentials in prompts or artifacts.
Before mutation, read AGENTS.md, contribution and maintainer docs, then inspect the default branch and effective protection. Repository-native commands and required checks take precedence over generic Rube operations.
If a repository provides a guarded merge or release command, use it instead of the generic merge tool. In agentic-awesome-skills, use antigravity-maintainer-batch-release and npm run merge:batch so exact-SHA review, fresh check-suite binding, and protected main are enforced.
Paginate until the requested result set is complete. Treat silent omission of labels or assignees as a permissions failure, not success.
MERGED and confirm the target branch contains the intended commit.Do not treat a successful API call that enables auto-merge or queues work as an immediate merge.
Deletion, force-push, default-branch changes, and protection changes are destructive or high-impact actions requiring explicit authorization.
workflow_dispatch support before dispatch.queued, in_progress, action_required, completed, and skipped states.Do not approve fork workflow runs by raw run ID when the repository provides a guarded approval command.
tools
Authorized security assessment of LLM applications and AI agents: prompt injection, tool abuse, RAG exposure, memory poisoning, system-prompt extraction, and agent-compliance engineering per OWASP LLM/ASI Top 10.
development
Builds two parameterized UI modes—流光溢彩白 (iridescent white) and 五彩斑斓黑 (colorful black)—with OKLCH, WebGL/CSS fallback, vision gating, screenshot QA, and total/per-color intensity reports. Use when a UI request names either mode or needs measured color parameters.
tools
Delegate coding tasks to the Kimi Code CLI (`kimi`) only when the user explicitly requests it, while the orchestrator retains review and landing responsibility.
development
Front-end JavaScript reverse engineering: locate signature chains, analyze encrypted request parameters, sample runtime behavior, and reproduce logic locally in Node for evidence-based output.