Files
optimclaw/skills/github/SKILL.md
T
[email protected]andClaude Opus 4.6 96266cb46d feat(skills): credential specs in skill frontmatter, HTTP tool hardening, mission leases
Skills can now declare API credentials in YAML frontmatter (SkillCredentialSpec,
SkillCredentialLocation, SkillOAuthConfig, ProviderRefreshStrategy). Valid specs
are registered into SharedCredentialRegistry at startup; the HttpTool auto-injects
credentials for matching hosts — same zero-exposure model as WASM tools.

HTTP tool security hardening:
- Block LLM-provided auth headers for hosts with registered credentials
- Return structured authentication_required error for missing credentials
- Strip sensitive response headers (Set-Cookie, WWW-Authenticate, Authorization)
- Scan response body through LeakDetector before returning to LLM

Mission capability leases: registered mission_create/list/fire/pause/resume/delete
as a "missions" capability so threads receive leases. Removed routine_* aliases
from effect adapter — descriptions mention "routine" for LLM intent mapping.

Includes 10 integration tests (tests/skill_credential_injection.rs) covering
the full pipeline: YAML parsing → validation → registry → HttpTool wiring →
per-user isolation.

Co-Authored-By: Claude Opus 4.6 (1M context) <[email protected]>
2026-03-27 19:33:58 -07:00

3.6 KiB

name, version, description, activation, credentials
name version description activation credentials
github 1.0.0 GitHub API integration via HTTP tool with automatic credential injection
keywords exclude_keywords patterns tags max_context_tokens
github
issues
pull request
repository
commit
branch
gitlab
bitbucket
(?i)(list|show|get|fetch|open|close|create|file|merge)\s.*(issue|PR|pull request|repo)
(?i)github.com
git
code-review
devops
2000
name provider location hosts oauth setup_instructions
github_token github
type
bearer
api.github.com
authorization_url token_url scopes refresh
https://github.com/login/oauth/authorize https://github.com/login/oauth/access_token
repo
read:org
strategy
reauthorize_only
Create a personal access token at https://github.com/settings/tokens

GitHub API Skill

You have access to the GitHub REST API via the http tool. Credentials are automatically injected — never construct Authorization headers manually. When the URL host is api.github.com, the system injects Authorization: Bearer {github_token} transparently.

API Patterns

All endpoints use https://api.github.com as the base URL. Common headers are injected automatically.

Issues

List issues:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/issues?state=open&sort=created&direction=desc&per_page=30")

Get single issue:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/issues/{number}")

Create issue:

http(method="POST", url="https://api.github.com/repos/{owner}/{repo}/issues", body={"title": "...", "body": "...", "labels": ["bug"]})

Add comment:

http(method="POST", url="https://api.github.com/repos/{owner}/{repo}/issues/{number}/comments", body={"body": "..."})

Pull Requests

List PRs:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/pulls?state=open&sort=created&direction=desc&per_page=30")

Create PR:

http(method="POST", url="https://api.github.com/repos/{owner}/{repo}/pulls", body={"title": "...", "body": "...", "head": "feature-branch", "base": "main", "draft": true})

Get PR diff:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/pulls/{number}", headers=[{"name": "Accept", "value": "application/vnd.github.v3.diff"}])

Repository

Get repo info:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}")

List branches:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/branches")

List recent commits:

http(method="GET", url="https://api.github.com/repos/{owner}/{repo}/commits?per_page=10")

Response Handling

  • GitHub returns JSON. Parse the response to extract relevant fields.
  • For list endpoints, check the Link header for pagination.
  • Rate limit: 5000 req/hour authenticated. Check X-RateLimit-Remaining header if doing bulk operations.
  • Errors return {"message": "..."} — always check for error responses.

Common Mistakes

  • Do NOT add an Authorization header — it is injected automatically by the credential system.
  • Always use HTTPS URLs (HTTP is blocked by the security layer).
  • For creating PRs, always set draft: true unless the user explicitly says "ready for review".
  • The state parameter for issues/PRs is open, closed, or all — not active/inactive.
  • Use per_page to control result count (max 100). Default is 30.