github-flow
GitHub issue/PR workflow automation. Topics — auth-scope (gh CLI priority + account mapping + batch scope refresh + 404 checklist), commit-message-discipline (commit message authoring + amend refresh + PUBLIC English enforcement), dependencies (blocked-by/sub-issues via GraphQL), epic-bundle (deferred findings → Epic + sub-issues), expand (expand-vs-split mid-work), identity-auth (gh account map + scope refresh + GH_TOKEN fallback), merge (CI/review gates + no autonomous push), plan-to-issue (MD → issue body), pr (PR with test plan), publish (branch + draft PR + CI watch + ready + merge, one topic), push-guards (branch/push-reject/force-push/main-push), register (dup check + strategy), review (structured comments), review-apply (deferred feedback apply), sanitize (PUBLIC repo personal data scan), upstream-issue (external OSS feature/bug). Use when: "plan to issue", "issue register", "create PR", "PR body", "code review", "merge PR", "PR squash", "sanitize", "PII", "expand PR", "blocked by", "epic bundle", "upstream issue", "review apply", "sub-issue", "gh auth", "force push", "push reject", "branch change forbid", "auth scope", "account mapping", "scope refresh", "commit message", "PUBLIC repo English".
Rank
62
Safety
84
Downloads
2.6k
Updated
Oct 9, 2026
Version
0.11.3
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.6K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.6K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.11.3release · observed Sep 27, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:github-flow- Install using `clawhub skill install s17ay1v6v88r2m102pvvc44gz183qcrm:github-flow` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/drumrobot/github-flow before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-github-flow/snapshot"
Documentation
CLAWHUB
156,612 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: github-flow metadata: author: es6kr version: "0.1.0" depends-on: - cleanup - code-workflow - web-browser description: | GitHub issue/PR workflow automation. Topics — auth-scope (gh CLI priority + account mapping + batch scope refresh + 404 checklist), commit-message-discipline (commit message authoring + amend refresh + PUBLIC English enforcement), dependencies (blocked-by/sub-issues via GraphQL), epic-bundle (deferred findings → Epic + sub-issues), expand (expand-vs-split mid-work), identity-auth (gh account map + scope refresh + GH_TOKEN fallback), merge (CI/review gates + no autonomous push), plan-to-issue (MD → issue body), pr (PR with test plan), publish (branch + draft PR + CI watch + ready + merge, one topic), push-guards (branch/push-reject/force-push/main-push), register (dup check + strategy), review (structured comments), review-apply (deferred feedback apply), sanitize (PUBLIC repo personal data scan), upstream-issue (external OSS feature/bug). Use when: "plan to issue", "issue register", "create PR", "PR body", "code review", "merge PR", "PR squash", "sanitize", "PII", "expand PR", "blocked by", "epic bundle", "upstream issue", "review apply", "sub-issue", "gh auth", "force push", "push reject", "branch change forbid", "auth scope", "account mapping", "scope refresh", "commit message", "PUBLIC repo English". --- # GitHub Flow Convert plans, research, and implementation results into GitHub issues and PRs. ## Topics | Topic | Description | Guide | |-------|-------------|-------| | auth-scope | gh CLI priority + account mapping + batch scope refresh + org-repo 404 checklist | [auth-scope.md](./auth-scope.md) | | commit-message-discipline | Commit message authoring, message update on amend, PUBLIC repo English enforcement, git operation type continuity, verb selection (`.md` as source code) | [commit-message-discipline.md](./commit-message-discipline.md) | | dependencies | Manage native Issue Relationships (blocked-by/blocking) via addBlockedBy/removeBlockedBy GraphQL mutations | [dependencies.md](./dependencies.md) | | epic-bundle | Bundle deferred review findings across multiple PRs into one Epic tracking issue (checklist + native sub-issues + epic label) | [epic-bundle.md](./epic-bundle.md) | | expand | Decide expand-vs-split when new findings emerge mid-work and update title/body | [expand.md](./expand.md) | | identity-auth | Owner-based gh account mapping for commit author identity + gh auth scope refresh + GH_TOKEN env fallback for org repo 404 | [identity-auth.md](./identity-auth.md) | | merge | CI success and AI review check then merge with commit cleanup, including pre-merge blockedBy verification | [merge.md](./merge.md) | | plan-to-issue | Convert plan/research MD to GitHub issue body or comments | [plan-to-issue.md](./plan-to-issue.md) | | pr | Create PR with structured body, test plan, and optional visual attachments. Every distinct PR number in an AskUserQuestion payload needs its own clickable URL
_meta.json
{
"ownerId": "kn74k8yfvftx6f062qa8fzyd8h8373jd",
"slug": "github-flow",
"version": "0.11.3",
"publishedAt": 1790524322009
}account-switch-merge.md
# Account-Switch Merge (`account-switch-merge`) Use this topic when performing a PR merge requiring a specific merger account (e.g., `DrumRobot` bot account for CI/release isolation or protected branch policies) with automatic post-merge account restoration. ## Purpose Automates the manual 6-condition check, temporary `gh auth` user switch, squash/merge execution, and guaranteed restoration of the developer's original GitHub account state. --- ## 6 Pre-Merge Conditions Checklist (MANDATORY) Before initiating an account switch or executing `gh pr merge`, ALL 6 conditions MUST be verified and pass: 1. **CI Success**: `gh pr checks <N>` returned all `SUCCESS` (no pending, no failed). 2. **AI Review Summary Posted**: `/consolidate pr <N>` has completed and the AI Review Summary comment is present (or PR is consolidate-exempt). 3. **Test Plan Checked**: All `- [ ]` checklist items in the PR body are marked completed (`- [x]`). 4. **Mergeable Status**: `gh pr view <N> --json mergeable` returns `"MERGEABLE"`. 5. **Base Branch Alignment**: PR is up to date with the latest base branch (no merge conflicts). 6. **Pre-Commit / Pre-Push Sanity**: Working tree is clean or changes are safely stashed. --- ## Automated 5-Step Account-Switch & Merge Protocol ### Step 1: Pre-Merge Verification ```bash # Verify 6 pre-merge conditions gh pr view <PR_NUMBER> --json state,mergeable,reviews,checks,body ``` ### Step 2: Record Current Active User ```bash ORIGINAL_USER=$(gh api user --jq .login) echo "Current active GH user: $ORIGINAL_USER" ``` ### Step 3: Switch to Target Merger Account If `$ORIGINAL_USER` is not the target merger account (e.g. `DrumRobot`), switch to it: ```bash TARGET_USER="DrumRobot" if [ "$ORIGINAL_USER" != "$TARGET_USER" ]; then gh auth switch -u "$TARGET_USER" fi ``` ### Step 4: Execute Squash & Merge ```bash gh pr merge <PR_NUMBER> --squash --delete-branch ``` ### Step 5: Guaranteed Original Account Restoration (HARD STOP) Regardless of merge success or failure, ALWAYS restore the original user account immediately: ```bash if [ "$ORIGINAL_USER" != "$TARGET_USER" ]; then gh auth switch -u "$ORIGINAL_USER" fi ``` Verify restored identity: ```bash gh api user --jq .login ``` --- ## Don't / Do Table | # | Don't | Do | |---|-------|----| | 1 | Merge without checking all 6 pre-merge conditions | Verify CI, Review, Test Plan, and Mergeable status BEFORE switching account | | 2 | Leave active `gh auth` as `DrumRobot` after merge | ALWAYS restore `$ORIGINAL_USER` in Step 5 immediately after merge | | 3 | Use direct `git push origin main` bypass | Always merge via `gh pr merge <N> --squash` |
auth-scope.md
# Auth Scope — gh CLI Priority + Account Mapping + Batch Scope Refresh + 404 Checklist ## gh CLI Priority and Browser Agent Restriction (HARD STOP) **All GitHub operations (PR lookup, review, comment, merge, etc.) must use the `gh` CLI tool first; routing around via a browser agent is strictly forbidden.** | # | Don't | Do | |---|-------|----| | 1 | Call a browser agent to check/consolidate PR reviews | Combine `gh pr view`, `gh api`, `gh pr checks`, etc. to extract data from the CLI | | 2 | Skip the CLI based on the subjective judgment "the browser is more accurate" | The `gh` CLI maintains auth and context — it is the most reliable source. Consider the browser only when the CLI fails | | 3 | Wait for browser rendering for simple info lookups (e.g., comment lists) | Parse JSON with `gh api`. Much faster and uses fewer tokens | Use the browser agent **only for special situations that are genuinely impossible via the CLI** (e.g., complex GUI configuration, visual layout verification), and only with prior user approval. ## Account Mapping (per organization) | Account | Purpose | git author identity | |---------|---------|---------------------| | `DrumRobot` | es6kr org repositories (es6kr/skills, claude-code-sessions, etc.) | `DrumRobot <[email protected]>` | | `<personal-account>` | Personal org / personal repositories | `<personal-account> <[email protected]>` | **Account switching**: `gh auth switch --user <account>`. On failure, inject `GH_TOKEN="$(gh auth token --user <account>)"` as an environment variable instead (must be passed via a script file — env vars are not preserved between separate Bash calls). ## commit author + PR account must map to repo owner (HARD STOP) **The gh account mapping applies not only to push/PR auth but also to commit author identity.** When committing/PRing to an es6kr org repository (including PUBLIC ones), proceeding with the `gh` active account still set to a non-primary account (a residual from other work) will permanently bake the wrong author into PUBLIC history. **Switch git author identity + gh account to match the repo owner before committing.** | # | Don't | Do | |---|-------|----| | 1 | Commit to an es6kr org repo while the active account is a non-primary account → wrong author baked in | Before committing: `git -C <repo> config user.name "<correct-name>" && git -C <repo> config user.email "<correct-email>"` | | 2 | Only switch the gh account for push/PR while leaving commit author as the wrong account | author + committer + push + PR must all match the repo owner's identity. Author is permanently recorded in PUBLIC history, so they must match | | 3 | Assume "auth is only needed at push time" | Commit author is baked in at commit time. An already-committed author can only be changed via amend/rebase | | 4 | Commit without checking the repo owner, relying on the current git config | Right before committing, run `git remote get-url origin` to confirm the owner → apply identity per the mappin
CHANGELOG.md
# Changelog ## [0.11.3](https://github.com/es6kr/skills/compare/github-flow-v0.11.2...github-flow-v0.11.3) (2026-09-27) ### Bug Fixes * **github-flow:** add optional graph-render dispatch for large epic-bundle bundles ([#549](https://github.com/es6kr/skills/issues/549)) ([45e3629](https://github.com/es6kr/skills/commit/45e362987eb52cf35272b484918a22c0fdd8bafc)) * **github-flow:** add PR-blocking-vehicle check before delivery-vehicle ask ([#550](https://github.com/es6kr/skills/issues/550)) ([89d9812](https://github.com/es6kr/skills/commit/89d98129de5530c7e13f827d5e3f7751b55bab97)) * **github-flow:** document IDE-subshell token override, merge-permission gap, and worktree sweep ([#546](https://github.com/es6kr/skills/issues/546)) ([ebb366a](https://github.com/es6kr/skills/commit/ebb366a06fde5d1f28b42cbc8d483fc335d3d9d3)) * **github-flow:** restore pre-merge state recheck in merge.md ([74ae392](https://github.com/es6kr/skills/commit/74ae39229444d0b039bb25bcb34cacea50ac1874)) ## [0.11.2](https://github.com/es6kr/skills/compare/github-flow-v0.11.1...github-flow-v0.11.2) (2026-09-24) ### Bug Fixes * **git-repo:** add prune_merged_worktrees.py + 7 accumulated fixes ([3d2ee94](https://github.com/es6kr/skills/commit/3d2ee9425285347d8f7e7698049d6e5769f73f92)) * **github-flow:** document multi-account and ssh remote publish gotchas ([4a772a8](https://github.com/es6kr/skills/commit/4a772a89adc8302f65da48c85e36588d2792f576)) ## [0.11.1](https://github.com/es6kr/skills/compare/github-flow-v0.11.0...github-flow-v0.11.1) (2026-09-20) ### Bug Fixes * **github-flow:** document the batch-script secret-echo gotcha for token injection ([91e3205](https://github.com/es6kr/skills/commit/91e320570dca3acfa9925f3a4afcb532e786d423)) ## [0.11.0](https://github.com/es6kr/skills/compare/github-flow-v0.10.2...github-flow-v0.11.0) (2026-09-18) ### Features * **task-plan,github-flow:** adopt artifact sibling guard in task-plan and prohibit multi-commit squash ([9938985](https://github.com/es6kr/skills/commit/9938985161fe1e0ddae934980b3c9307e7dfd5f4)) ### Bug Fixes * **cleanup:** make the session-end report table self-sufficient ([#487](https://github.com/es6kr/skills/issues/487)) ([c4a0255](https://github.com/es6kr/skills/commit/c4a02557fb8de3b32cf337c549f62535dabf824b)) * **github-flow:** prohibit squash merge on multi-commit PRs in skills and plugins repos ([8db57f8](https://github.com/es6kr/skills/commit/8db57f8fe76357bda3f3d26fed7e4c253bfffbb3)) ## [0.10.2](https://github.com/es6kr/skills/compare/github-flow-v0.10.1...github-flow-v0.10.2) (2026-09-08) ### Bug Fixes * **github-flow:** document merge-commit policy, promotion PR discipline, and develop routing ([ace6bd4](https://github.com/es6kr/skills/commit/ace6bd4d445a2f805a8183946f70bdf34d48289f)) ## [0.10.1](https://github.com/es6kr/skills/compare/github-flow-v0.10.0...github-flow-v0.10.1) (2026-09-01) ### Bug Fixes * **githooks:** fix set -e crash in BASE-7 guard + weigh review-cost in pr.md Step
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/drumrobot/skills/github-flow",
"sourceUrl": "https://clawhub.ai/drumrobot/skills/github-flow",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T12:44:38.185Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-github-flow/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-github-flow/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T12:44:38.185Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.6K downloads",
"href": "https://clawhub.ai/drumrobot/github-flow",
"sourceUrl": "https://clawhub.ai/drumrobot/github-flow",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T12:44:38.185Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.11.3",
"href": "https://clawhub.ai/drumrobot/github-flow",
"sourceUrl": "https://clawhub.ai/drumrobot/github-flow",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-27T15:52:02.009Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-github-flow/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-drumrobot-github-flow/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.11.3",
"description": "- Documentation updates across multiple guides, including CHANGELOG.md, epic-bundle.md, identity-auth.md, merge.md, pr.md, and publish.md - Removed deprecated or obsolete file: skill-card.md - No changes to core logic or code functionality; updates focus on content and guide maintenance",
"href": "https://clawhub.ai/drumrobot/github-flow",
"sourceUrl": "https://clawhub.ai/drumrobot/github-flow",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-09-27T15:52:02.009Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
