github-autosetup
自动化配置 pi 在 GitHub/git 的行动(纯 Git Bash 驱动):环境探测 → 传输通道决策(https/GCM 或 SSH)→ 浏览器 OAuth → 带口令 SSH 密钥 + agent → 建仓推送 → post-commit 自动推送 + 计划任务兜底。内置敏感信息传递 SOP(令牌/口令/密钥/cookie 零明文)。当用户说"配置 github / 自动推送 / 建仓库 / 推送仓库 / 配置 git"时使用。 Skill: github-autosetup Owner: sgtbaixiao Summary: 自动化配置 pi 在 GitHub/git 的行动(纯 Git Bash 驱动):环境探测 → 传输通道决策(https/GCM 或 SSH)→ 浏览器 OAuth → 带口令 SSH 密钥 + agent → 建仓推送 → post-commit 自动推送 + 计划任务兜底。内置敏感信息传递 SOP(令牌/口令/密钥/cookie 零明文)。当用户说"配置 github / 自动推送 / 建仓库 / 推送仓库 / 配置 git"时使用。 Tags: latest:0.1.0 Version history: v0.1.0 | 2026-08-09T13:38:48.759Z | auto Initial public release with full automated GitHub/git setup via Git Ba
Rank
62
Safety
84
Downloads
2.1k
Updated
Oct 9, 2026
Version
0.1.0
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.1K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.1K downloadsadoption · observed Oct 9, 2026
- Latest release
- 0.1.0release · observed Aug 9, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s172yq424m3anmm92ags91c9xx8c5ac5:github-autosetup- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-sgtbaixiao-github-autosetup/snapshot"
Documentation
CLAWHUB
13,211 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: github-autosetup
description: 自动化配置 pi 在 GitHub/git 的行动(纯 Git Bash 驱动):环境探测 → 传输通道决策(https/GCM 或 SSH)→ 浏览器 OAuth → 带口令 SSH 密钥 + agent → 建仓推送 → post-commit 自动推送 + 计划任务兜底。内置敏感信息传递 SOP(令牌/口令/密钥/cookie 零明文)。当用户说"配置 github / 自动推送 / 建仓库 / 推送仓库 / 配置 git"时使用。
license: MIT
compatibility: pi, Claude Code(Git Bash / bash 环境;Windows 已验证,macOS/Linux 标注分支)
metadata:
author: Sgt_BaiXiao
version: "2.0.0"
homepage: https://github.com/SgtBaixiao/github-autosetup
---
# GitHub AutoSetup v2 — 自动化 GitHub/git 配置(纯 Git Bash 驱动)
把 pi(或任意 agent)机器上的 GitHub/git 一次性配置到"提交即自动推送",全程**敏感信息零明文**。**所有自动化通过 Git Bash 完成**(agent 的 bash 工具或用户 Git Bash 终端)。
> **为什么不用 PowerShell**(v1 血泪教训):Windows PowerShell 5.1 有三大坑 —— UTF-8 无 BOM 按 GBK 误读、`Encoding::UTF8` 写文件带 BOM 破坏 `#!/bin/sh`、原生命令引号解析(逗号列表绑成单串/内嵌引号被吞)。bash 侧这些全部不存在。本 skill 从 v1 失败中重建,已验证:Windows 11 + Git Bash + 大陆网络(github.com:443 被阻断)场景。
---
## 0. 敏感信息传递 SOP(先读,违反即事故)
**铁律:任何密钥、令牌、口令、cookie 都不得进入对话文本、仓库、日志明文。**
| 敏感物 | 正确传递方式 | 错误方式 |
|---|---|---|
| GitHub 令牌 | **一律浏览器 OAuth**(`gh auth login -w`),令牌入系统 keyring(Windows=DPAPI) | 让用户把 token 粘贴进对话/文件 |
| SSH 私钥 | **交互式 `ssh-keygen`(必须设口令)**,用户在自己 Git Bash 输入;解锁态驻 ssh-agent 内存 | `-N ""` 空口令;口令打进命令行参数 |
| 口令/密码 | 只出现在用户终端的交互提示中 | 发聊天里 |
| 站点 cookie(B站/贴吧) | 导出 JSON → 写**仓库外临时文件** → 转换后写入**已 gitignore 的 config** → 删临时文件;验证输出**掩码** | 把 cookie 原文粘贴进对话/提交 |
| 敏感文件落点 | 核查权限(`icacls`/`chmod 700`);报告落点(keyring vs 文件) | 不核查直接收工 |
**操作模式**:agent 打印"**终端复制块**"(用户在自己 Git Bash 执行)或直接用自身 bash 工具执行;agent 只**验证结果**(`gh auth status` / `ssh-add -l` / `git ls-remote`),全程看不见秘密。验证输出一律掩码(`sed 's/Token: .*/Token: ***/'`)。
---
## 1. 环境探测(只读,bash)
```bash
bash "<skill_dir>/scripts/probe.sh"
```
输出:git/gh/GCM/ssh-agent、git 身份、**网络通道**(github.com:443 / api.github.com:443 / github.com:22 / ssh.github.com:443)、现有密钥、gh 认证态(token 类型掩码)。
**通道决策表**:
| 探测结果 | 走哪条路 |
|---|---|
| `github.com:443` 通 | https + GCM(DPAPI 加密,最优) |
| 443 断但 `github.com:22` 或 `ssh.github.com:443` 通 | **SSH + 带口令密钥 + agent**(大陆网络常见) |
| 全断 | 报告:需代理/镜像或手动网页,不硬推 |
| `api.github.com` 通但 `github.com` 断 | 混合:gh API 建仓 + git 走 SSH(本机实测案例) |
## 2. 认证(HITL,两处需用户本人 Git Bash 操作)
**① gh 浏览器 OAuth**(未认证或令牌是 fine-grained PAT 时):
```bash
gh auth login -h github.com -p <https|ssh> -w
```
- **前提核查**:`gh auth status` 显示 `Token: github_pat_*` → fine-grained PAT **无法建仓**(GitHub 官方限制),必须重走浏览器 OAuth(`ghp_` 才可建仓)。
- 认证后核查:`gh auth status` 显示 `(keyring)` 即合格;hosts.yml 只应含元数据。
**② SSH 密钥(带口令)+ agent**(用户 Git Bash):
```bash
ssh-keygen -t ed25519 -f ~/.ssh/id_ed25519_gh -C "autopush" # 输入口令两次,别留空
ssh-add ~/.ssh/id_ed25519_gh
```
- agent 未启用:`powershell -c "Set-Service ssh-agent -StartupType Automatic; Start-Service ssh-agent"`(仅此一步用 PowerShell,或用户管理员终端)。
- 注册公钥:`gh ssh-key add ~/.ssh/id_ed25519_gh.pub --title "autopush"`(token 无权限时用户网页粘贴 .pub,.pub 可公开展示)。
- `~/.ssh/config` 追加(多密钥防混乱):
```
Host github.com
HostName github.com
User git
IdentityFile ~/.ssh/id_ed25519_gh
IdentitiesOnly yes
```
- 验证:`ssh -T git@githuREADME.md
# github-autosetup — 自动化 GitHub/git 配置(Agent Skill · v2 纯 Git Bash 驱动) 把 pi(或任意 agent)机器的 GitHub/git 一次配置到**提交即自动推送**,内置**敏感信息零明文 SOP**。 - **纯 Git Bash 驱动**(v1 的 PowerShell 路线已废弃,见 v1 教训:PS5.1 编码/BOM/引号三大坑) - 通道自动决策:https+GCM(DPAPI 加密)优先,被阻断自动切 SSH(带口令密钥 + agent) - 认证走浏览器 OAuth + 交互式密钥生成(**绝不要求用户粘贴 token/口令**) - 建仓推送、post-commit 自动推送 hook、计划任务兜底(全 bash) - 实机验证:Windows 11 + 大陆网络(github.com:443 被阻断场景)✅ ## 安装(各平台) > 发布约定:本仓库每次上架新平台后,都会在此补齐对应安装指令。当前已发布:GitHub。 | 平台 | 安装方式 | 状态 | |---|---|---| | **GitHub(源)** | `git clone https://github.com/SgtBaixiao/github-autosetup` | ✅ 已发布 | | **pi** | `cp -r github-autosetup ~/.pi/agent/skills/github-autosetup`(或 clone 后复制) | ✅ 可用 | | **Claude Code** | 个人:`git clone ... ~/.claude/skills/github-autosetup`;或插件:`/plugin install github-autosetup@<marketplace>`(市场就绪后) | ✅ 可克隆 | | **Codex / OpenCode** | `cp -r github-autosetup ~/.codex/skills/` / `~/.opencode/skills/` | ✅ 可克隆 | | **Hugging Face CLI** | `hf skills add https://github.com/SgtBaixiao/github-autosetup` | ⏳ 上架后 | | **Agent Skill Hub** | `skhub add SgtBaixiao/github-autosetup` | ⏳ 待导入(需账号) | | **Skillstore** | `skillstore install github-autosetup` | ⏳ 待提交(需账号) | | **Claude 社区市场** | `/plugin install github-autosetup@claude-community` | ⏳ 待提交(需账号) | > 平台账号类发布(Agent Skill Hub / Skillstore / Claude 市场 / HF)为一次性浏览器操作,见 `Skill/README.md` 发布手册。 ## 使用 对 agent 说:"配置我的 GitHub 自动推送",agent 按 SKILL.md 流程执行: 1. `scripts/probe.sh` 探测环境与通道 2. 按决策表走 https 或 SSH;打印"终端复制块"让你完成交互认证(浏览器 OAuth / 带口令密钥) 3. 建仓推送(可见性向你确认) 4. `bash scripts/install-autopush.sh -d <outdir> -t AutoSync -m 30 <repo1> <repo2> ...` 5. 实测自动推送 + 安全自检 ## 结构 ``` github-autosetup/ ├── SKILL.md # 完整 SOP(Git Bash 驱动 + 敏感信息规范 + 决策表 + 故障排查) ├── scripts/ │ ├── probe.sh # 只读环境/网络/凭据探测(含掩码) │ ├── install-autopush.sh # 装 post-commit hooks + 生成 autopush.sh + schtasks 注册(纯 bash) │ └── autopush.sh # 自动提交+推送(由 install 生成,无凭据) ├── README.md / LICENSE / .gitignore / .claude-plugin/plugin.json ``` ## 安全承诺 - 令牌:浏览器 OAuth → 系统 keyring(Windows DPAPI 加密) - 私钥:**必须设口令**,解锁态仅驻 ssh-agent 内存 - 无任何 token/口令写入仓库、日志、对话明文;敏感文件权限核查 - cookie 类配置:临时文件转换 → gitignore 的 config → 删除临时文件 → 掩码验证 ## License MIT © Sgt_BaiXiao v2 verified 1786282218
_meta.json
{
"ownerId": "kn70zc8xyczzxmfzbjft9gveks8c4j27",
"slug": "github-autosetup",
"version": "0.1.0",
"publishedAt": 1786282728759
}skill-card.md
## Description: Automates GitHub and git setup for coding agents through Git Bash, including environment probing, HTTPS or SSH path selection, browser OAuth, passphrase-protected SSH keys, repository creation and push, and post-commit auto-push setup. This skill is ready for commercial/non-commercial use. ## Publisher: [sgtbaixiao](https://clawhub.ai/user/sgtbaixiao) ### License/Terms of Use: MIT ## Use Case: Developers and agent operators use this skill to configure GitHub authentication, create and push repositories, and install auto-push workflows for selected local repositories while keeping credentials out of chat, logs, and repository files. ### Deployment Geography for Use: Global ## Known Risks and Mitigations: Risk: Persistent automation can commit and push repository changes without fresh review. Mitigation: Install only for repositories where unattended publishing is intended, confirm repository visibility, and review the generated hooks and scheduled task before relying on them. Risk: Repositories that contain secrets or unfinished work could be enrolled in auto-push by mistake. Mitigation: Use strong .gitignore rules, secret scanning, and explicit repository selection before installing auto-push automation. Risk: Installed post-commit hooks and Windows scheduled tasks may continue running after initial setup. Mitigation: Document how to remove the hooks and scheduled task, and verify the setup after installation with git status, git ls-remote, and scheduled-task checks. ## Reference(s): - [GitHub Repository](https://github.com/SgtBaixiao/github-autosetup) - [ClawHub Skill Page](https://clawhub.ai/sgtbaixiao/skills/github-autosetup) ## Skill Output: **Output Type(s):** [Guidance, Markdown, Shell commands, Code, Configuration] **Output Format:** [Markdown guidance with bash and shell command snippets] **Output Parameters:** [1D] **Other Properties Related to Output:** [Includes human-in-the-loop prompts for browser OAuth, SSH key passphrases, repository visibility, and post-install verification.] ## Skill Version(s): 0.1.0 (source: ClawHub release metadata) ## Ethical Considerations: Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
.claude-plugin/plugin.json
{
"name": "github-autosetup",
"description": "Automated GitHub/git setup for coding agents, driven purely through Git Bash: probe → channel decision (https/GCM or SSH) → browser-OAuth auth → passphrase SSH key + agent → repo create/push → post-commit auto-push + scheduled task. Zero plaintext secrets (sensitive-info SOP built in).",
"version": "2.0.0",
"author": {
"name": "Sgt_BaiXiao"
},
"homepage": "https://github.com/SgtBaixiao/github-autosetup",
"repository": "https://github.com/SgtBaixiao/github-autosetup",
"license": "MIT"
}AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/sgtbaixiao/skills/github-autosetup",
"sourceUrl": "https://clawhub.ai/sgtbaixiao/skills/github-autosetup",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:23:36.861Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sgtbaixiao-github-autosetup/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sgtbaixiao-github-autosetup/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T18:23:36.861Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.1K downloads",
"href": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceUrl": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T18:23:36.861Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "0.1.0",
"href": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceUrl": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-09T13:38:48.759Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-sgtbaixiao-github-autosetup/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-sgtbaixiao-github-autosetup/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 0.1.0",
"description": "Initial public release with full automated GitHub/git setup via Git Bash: - Automated end-to-end configuration: environment detection, protocol selection, browser OAuth, SSH key generation with passphrase, repository creation, and auto-push setup. - Pure Git Bash implementation; PowerShell completely avoided due to encoding/permission issues. - Sensible default security: no secrets/tokens/passwords appear in logs, history, or chat; all sensitive operations via interactive terminal or system keyring. - Supports both https+GCM and SSH channels based on network reachability. - Automatically installs post-commit hook and scheduled tasks for reliable auto-push operation. - Comprehensive troubleshooting, security self-check, and support for Windows (Git Bash verified), macOS/Linux (with adjustments).",
"href": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceUrl": "https://clawhub.ai/sgtbaixiao/github-autosetup",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-08-09T13:38:48.759Z",
"isPublic": true
}
]
}Record generated Oct 10, 2026.
