GitHub Workflow
Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review,...
Rank
62
Safety
84
Downloads
1.2k
Updated
Oct 11, 2026
Version
1.3.5
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 11, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 11, 2026
- Adoption signal
- 1.2K downloadsadoption · observed Oct 11, 2026
- Latest release
- 1.3.5release · observed May 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s174w9qs6gjhqm0m23ef8vqejn866qsf:github-project-workflow- Install using `clawhub skill install s174w9qs6gjhqm0m23ef8vqejn866qsf:github-project-workflow` in an isolated environment before connecting it to live workloads.
- No published capability contract is available yet, so validate auth and request/response behavior manually.
- Review the upstream CLAWHUB listing at https://clawhub.ai/kretkas/github-project-workflow before using production credentials.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/snapshot"
Documentation
CLAWHUB
142,714 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
--- name: GitHub Workflow description: "Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. Trigger on: GitHub, git, gh CLI, repo, PR, branch, merge, commit, issue, release, CI, GitHub Actions, tag, secret." --- # GitHub Skill ## Agent Directives These are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks. ### On skill installation When this skill is first loaded, introduce it to the user: - Explain that all project work will now follow a professional GitHub workflow - Mention: branching strategy, work logs, CI checks, semantic versioning, security rules - Ask: "Do you have an existing project, or are we starting a new one?" ### On new project **If this is the user's first project ever:** - Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else - Offer to create a new repo: name, visibility (public/private), license, .gitignore - Set up branch protection on `main` and `develop` right away - Clone into `~/workspace/projects/<repo-name>/` - Create initial `develop` branch - Confirm setup is complete before starting any work **If the user already has projects:** - Ask which repo they want to work on, or detect from context - Clone into `~/workspace/projects/<repo-name>/` if not already there - Verify branch protection is in place — if not, offer to set it up - Proceed directly to task workflow ### On continuing existing work When the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes. ### On every task - Assess task scale first (see Task scale table in Agent Workflow). - Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge. - Normal/significant tasks: Issue and work log are mandatory before branching. - Never commit directly to `main` or `develop`. - Never skip the pre-PR checklist on normal/significant tasks. - Never expose tokens, secrets, or credentials in any command or output. - If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**. ### On using this skill - This file (SKILL.md) is always in context — use it for workflow, branching, work log rules. - Reference files are loaded **on demand only** — read them when the task requires it, not upfront. - Work log is not optional — it is part of every task from start to finish. - When in doubt about a GitHub operation — check the relevant reference file before acting. --- ## Security (always) - All operations via `gh` CLI. Always `--repo owner/repo` outside a git directory. - Auth: `gh
_meta.json
{
"ownerId": "kn71braj4mtw6xbr2sbydm0p6s866qsx",
"slug": "github-project-workflow",
"version": "1.3.5",
"publishedAt": 1778345744786
}references/api-queries.md
# API Queries, Search & Audit
## Issues
```bash
gh issue list --repo owner/repo --label "bug" --state open
gh issue list --repo owner/repo --assignee "@me"
gh issue create --repo owner/repo --title "..." --body "..." --label "bug"
# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue
gh issue comment 42 --repo owner/repo --body "Fixed in #55, released in v1.2.1"
# ⚠️ CONFIRM WITH USER before running — closes the issue
gh issue close 42 --repo owner/repo
# In commits always: "fixes #42" / "closes #42" / "resolves #42"
```
## JSON queries
```bash
gh pr list --repo owner/repo \
--json number,title,state,mergeable,reviewDecision \
--jq '.[] | "\(.number): \(.title) [\(.state)]"'
gh issue list --repo owner/repo \
--json number,title,labels \
--jq '.[] | "\(.number): \(.title) | \([.labels[].name]|join(","))"'
gh api repos/owner/repo/issues --paginate --jq '.[].title'
```
## Audit
```bash
# Recent commits
gh api repos/owner/repo/commits \
--jq '.[:10][] | "\(.sha[:7]) \(.commit.author.name): \(.commit.message|split("\n")[0])"'
# PR for a commit
gh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|"#\(.number) \(.title)"'
# Search TODOs
gh api search/code --field q="TODO repo:owner/repo" \
--jq '.items[] | "\(.path): \(.text_matches[0].fragment)"'
# Repo stats
gh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'
```references/ci-actions.md
# CI / GitHub Actions
## Runs
```bash
gh run list --repo owner/repo --limit 10
gh run watch --repo owner/repo
gh run view <id> --repo owner/repo --log-failed
gh run rerun <id> --repo owner/repo --failed-only
gh run rerun <id> --repo owner/repo
# ⚠️ CONFIRM WITH USER before running — cancels an active run
gh run cancel <id> --repo owner/repo
```
## Workflows
```bash
gh workflow list --repo owner/repo
# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)
gh workflow run deploy.yml --repo owner/repo --field environment=staging
# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)
gh workflow enable deploy.yml --repo owner/repo
# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)
gh workflow disable deploy.yml --repo owner/repo
```
## Checklist for .github/workflows/
- Pin actions to SHA (not `@latest`)
- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode
- Cache deps: `actions/cache`
- Tests on every PR; deploy only on merge to main
- Use `environments:` with required reviewers for production
- Always declare `permissions:` explicitly — default is too broad
```yaml
# Minimal safe permissions example
permissions:
contents: read
pull-requests: write
```references/pull-requests.md
# Pull Requests ## Create ```bash gh pr create --repo owner/repo \ --title "feat: description (#42)" \ --body "## What\n...\n## Why\nCloses #42\n## Testing\n- [ ] tests pass" \ --base develop --head feature/branch \ --label "feature" --assignee "@me" gh pr create ... --draft # WIP gh pr ready 55 --repo owner/repo # promote draft ``` ## Review & Inspect ```bash gh pr view 55 --repo owner/repo gh pr diff 55 --repo owner/repo gh pr checks 55 --repo owner/repo gh pr review 55 --approve --body "LGTM" gh pr review 55 --request-changes --body "..." gh pr comment 55 --body "..." ``` ## Merge strategies ```bash # ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch gh pr merge 55 --squash --delete-branch --repo owner/repo # features (clean history) gh pr merge 55 --merge --repo owner/repo # releases (preserve history) gh pr merge 55 --rebase --delete-branch --repo owner/repo # linear history ``` ## List ```bash gh pr list --repo owner/repo gh pr list --repo owner/repo --assignee "@me" gh pr list --repo owner/repo --json number,title,state,reviewDecision \ --jq '.[] | "\(.number): \(.title) [\(.reviewDecision // "pending")]"' ``` ## Close without merging ```bash # ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded) gh pr close 55 --repo owner/repo --comment "Closing — superseded by #60" ```
AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/kretkas/skills/github-project-workflow",
"sourceUrl": "https://clawhub.ai/kretkas/skills/github-project-workflow",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T02:54:32.811Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-11T02:54:32.811Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "1.2K downloads",
"href": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceUrl": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-11T02:54:32.811Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.3.5",
"href": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceUrl": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-09T16:55:44.786Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.3.5",
"description": "github-project-workflow 1.3.5 - Updated trigger instructions in the skill description for clarity; now lists more specific keywords including \"gh CLI\" and \"GitHub Actions\". - Added explicit note to the Quick Reference: all write operations now require explicit user confirmation (⚠️), reinforcing safety for critical actions. - Minor clarifications and formatting updates for improved readability. - No file or workflow behavior changes introduced.",
"href": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceUrl": "https://clawhub.ai/kretkas/github-project-workflow",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-05-09T16:55:44.786Z",
"isPublic": true
}
]
}Record generated Oct 11, 2026.
