{"id":"ae0e34ae-6869-4429-90e5-cebb9da38fe5","entityType":"agent","slug":"clawhub-kretkas-github-project-workflow","name":"GitHub Workflow","canonicalUrl":"https://www.xpersona.co/agent/clawhub-kretkas-github-project-workflow","canonicalPath":"/agent/clawhub-kretkas-github-project-workflow","generatedAt":"2026-10-11T05:28:11.015Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":null},"description":"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review,...","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.2K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s174w9qs6gjhqm0m23ef8vqejn866qsf:github-project-workflow","sourceUrl":"https://clawhub.ai/kretkas/github-project-workflow","homepage":"https://clawhub.ai/kretkas/skills/github-project-workflow","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/kretkas/github-project-workflow","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/kretkas/skills/github-project-workflow","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"GitHub Workflow technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":null},"stars":null,"forks":null,"downloads":1182,"packageName":null,"latestVersion":"1.3.5","tractionLabel":"1.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:54:32.797Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T02:54:32.811Z","lastCrawledAt":"2026-10-11T02:54:32.797Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T02:54:32.797Z","lastVerifiedAt":null,"highlights":[{"version":"1.3.5","createdAt":"2026-05-09T16:55:44.786Z","changelog":"github-project-workflow 1.3.5 - Updated trigger instructions in the skill description for clarity; now lists more specific keywords including \"gh CLI\" and \"GitHub Actions\". - Added explicit note to the Quick Reference: all write operations now require explicit user confirmation (⚠️), reinforcing safety for critical actions. - Minor clarifications and formatting updates for improved readability. - No file or workflow behavior changes introduced.","fileCount":9,"zipByteSize":11397},{"version":"1.3.4","createdAt":"2026-05-07T23:35:55.955Z","changelog":"- Removed incorrect `⚠️ CONFIRM WITH USER` warning from `gh issue create` in `api-queries.md` — creating an issue is non-destructive and reversible, the warning was inconsistent with the rest of the skill's confirmation policy","fileCount":8,"zipByteSize":10102},{"version":"1.3.3","createdAt":"2026-05-07T23:23:15.236Z","changelog":"- Improved the tiny task workflow: now a pull request and explicit user confirmation are always required before merging. - Enhanced CI failure handling in the normal/significant task process: agents must now download failed logs, record causes in the work log, and fix issues before proceeding. - Updated the pre-PR checklist: mandatory self-review after all other checks to ensure quality before requesting human review. - Clarified task sequence, user confirmation points, and work log requirements for better reliability and transparency.","fileCount":8,"zipByteSize":9700},{"version":"1.3.2","createdAt":"2026-05-07T22:57:48.782Z","changelog":"**Summary:** Adds explicit task scale assessment and introduces a simplified workflow (\"quick log\") for tiny tasks. - Requires assessing task scale (tiny / normal / significant) before starting any work. - Tiny tasks (≤2 files, cosmetic/config, no backend/infra): skip Issue, PR, full work log — use quick-log.md and direct merge. - Normal/significant tasks: follow standard Issue, branch, PR, work log process. - Updated task process table and agent directives to reflect scale-based branching. - No changes to files detected; documentation/workflow rules only.","fileCount":8,"zipByteSize":9209},{"version":"1.3.1","createdAt":"2026-05-07T18:40:10.494Z","changelog":"- Expands the workflow trigger: this skill now applies to any software development, coding task, bug fix, feature, or project work—even if GitHub or git are not mentioned. - Updated description to clarify when to invoke the workflow: using this skill is now required whenever the user asks for code writing, project file modification, or error fixing. - Workflow logic and agent behavior remain unchanged. Only the activation rules and description were broadened. - No file or implementation changes beyond the skill's audience and trigger conditions.","fileCount":8,"zipByteSize":8636},{"version":"1.3.0","createdAt":"2026-05-07T18:29:35.344Z","changelog":"Version 1.3.0 — Major skill upgrade with explicit agent workflow and project lifecycle automation. - Introduces mandatory agent directives covering skill installation, new project setup, and session workflows. - Adds a structured work log system for every task to ensure state tracking and session continuity. - Expands branching model and workspace rules for consistency and safety in all project work. - Enforces pre-task issue creation, branch protection, and security checks. - Provides detailed checklists and \"when to act\" instructions for common situations. - Skill now covers the entire GitHub-based project lifecycle, from repo setup and branching to CI, releases, and secrets management.","fileCount":8,"zipByteSize":8594},{"version":"1.2.0","createdAt":"2026-05-06T23:24:56.209Z","changelog":"# Changed - Split into `SKILL.md` (core) + 6 reference files — only the relevant section is loaded - ~70% token reduction on typical tasks # Added - `⚠️ CONFIRM WITH USER` warnings before all write/delete operations - Git Flow branching strategy: `main → develop → feature/fix/hotfix/release` - Branch protection via `gh api` - Semantic versioning with MAJOR/MINOR/PATCH table - Full 10-step workflow: issue → branch → PR → merge → release - CI best practices checklist for `.github/workflows/` - Security rules: no token exposure, `gh auth login --web` only # Removed - Monolithic single-file structure","fileCount":8,"zipByteSize":5450},{"version":"1.1.0","createdAt":"2026-05-06T23:17:35.738Z","changelog":"**Summary:** Added comprehensive reference documentation and migrated to professional `gh` CLI workflows. - Switched to the `gh` CLI for all GitHub operations; removed previous MorphixAI integration. - Added six reference files covering repo setup, pull requests, CI actions, releases, secrets, and API queries. - Documented security best practices: authentication, secret handling, branch protection. - Provided concise command references for common GitHub tasks. - Detailed standard branching model and commit conventions.","fileCount":8,"zipByteSize":4892}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s174w9qs6gjhqm0m23ef8vqejn866qsf:github-project-workflow","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s174w9qs6gjhqm0m23ef8vqejn866qsf:github-project-workflow` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/kretkas/github-project-workflow before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T05:28:11.011Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-kretkas-github-project-workflow/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":null},"readme":"Skill: GitHub Workflow\n\nOwner: kretkas\n\nSummary: Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review,...\n\nTags: latest:1.3.5\n\nVersion history:\n\nv1.3.5 | 2026-05-09T16:55:44.786Z | user\n\ngithub-project-workflow 1.3.5\n\n- Updated trigger instructions in the skill description for clarity; now lists more specific keywords including \"gh CLI\" and \"GitHub Actions\".\n- Added explicit note to the Quick Reference: all write operations now require explicit user confirmation (⚠️), reinforcing safety for critical actions.\n- Minor clarifications and formatting updates for improved readability.\n- No file or workflow behavior changes introduced.\n\nv1.3.4 | 2026-05-07T23:35:55.955Z | user\n\n- Removed incorrect `⚠️ CONFIRM WITH USER` warning from `gh issue create` in `api-queries.md` — creating an issue is non-destructive and reversible, the warning was inconsistent with the rest of the skill's confirmation policy\n\nv1.3.3 | 2026-05-07T23:23:15.236Z | user\n\n- Improved the tiny task workflow: now a pull request and explicit user confirmation are always required before merging.\n- Enhanced CI failure handling in the normal/significant task process: agents must now download failed logs, record causes in the work log, and fix issues before proceeding.\n- Updated the pre-PR checklist: mandatory self-review after all other checks to ensure quality before requesting human review.\n- Clarified task sequence, user confirmation points, and work log requirements for better reliability and transparency.\n\nv1.3.2 | 2026-05-07T22:57:48.782Z | user\n\n**Summary:**  \nAdds explicit task scale assessment and introduces a simplified workflow (\"quick log\") for tiny tasks.\n\n- Requires assessing task scale (tiny / normal / significant) before starting any work.\n- Tiny tasks (≤2 files, cosmetic/config, no backend/infra): skip Issue, PR, full work log — use quick-log.md and direct merge.\n- Normal/significant tasks: follow standard Issue, branch, PR, work log process.\n- Updated task process table and agent directives to reflect scale-based branching.\n- No changes to files detected; documentation/workflow rules only.\n\nv1.3.1 | 2026-05-07T18:40:10.494Z | user\n\n- Expands the workflow trigger: this skill now applies to any software development, coding task, bug fix, feature, or project work—even if GitHub or git are not mentioned.\n- Updated description to clarify when to invoke the workflow: using this skill is now required whenever the user asks for code writing, project file modification, or error fixing.\n- Workflow logic and agent behavior remain unchanged. Only the activation rules and description were broadened.\n- No file or implementation changes beyond the skill's audience and trigger conditions.\n\nv1.3.0 | 2026-05-07T18:29:35.344Z | user\n\nVersion 1.3.0 — Major skill upgrade with explicit agent workflow and project lifecycle automation.\n\n- Introduces mandatory agent directives covering skill installation, new project setup, and session workflows.\n- Adds a structured work log system for every task to ensure state tracking and session continuity.\n- Expands branching model and workspace rules for consistency and safety in all project work.\n- Enforces pre-task issue creation, branch protection, and security checks.\n- Provides detailed checklists and \"when to act\" instructions for common situations.\n- Skill now covers the entire GitHub-based project lifecycle, from repo setup and branching to CI, releases, and secrets management.\n\nv1.2.0 | 2026-05-06T23:24:56.209Z | user\n\n# Changed\n- Split into `SKILL.md` (core) + 6 reference files — only the relevant section is loaded\n- ~70% token reduction on typical tasks\n\n# Added\n- `⚠️ CONFIRM WITH USER` warnings before all write/delete operations\n- Git Flow branching strategy: `main → develop → feature/fix/hotfix/release`\n- Branch protection via `gh api`\n- Semantic versioning with MAJOR/MINOR/PATCH table\n- Full 10-step workflow: issue → branch → PR → merge → release\n- CI best practices checklist for `.github/workflows/`\n- Security rules: no token exposure, `gh auth login --web` only\n\n# Removed\n- Monolithic single-file structure\n\nv1.1.0 | 2026-05-06T23:17:35.738Z | user\n\n**Summary:** Added comprehensive reference documentation and migrated to professional `gh` CLI workflows.\n\n- Switched to the `gh` CLI for all GitHub operations; removed previous MorphixAI integration.\n- Added six reference files covering repo setup, pull requests, CI actions, releases, secrets, and API queries.\n- Documented security best practices: authentication, secret handling, branch protection.\n- Provided concise command references for common GitHub tasks.\n- Detailed standard branching model and commit conventions.\n\nArchive index:\n\nArchive v1.3.5: 9 files, 11397 bytes\n\nFiles: references/api-queries.md (1433b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), skill-card.md (2333b), SKILL.md (13135b), _meta.json (142b)\n\nFile v1.3.5:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. Trigger on: GitHub, git, gh CLI, repo, PR, branch, merge, commit, issue, release, CI, GitHub Actions, tag, secret.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n### On every task\n- Assess task scale first (see Task scale table in Agent Workflow).\n- Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge.\n- Normal/significant tasks: Issue and work log are mandatory before branching.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist on normal/significant tasks.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n## Security (always)\n- All operations via `gh` CLI. Always `--repo owner/repo` outside a git directory.\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\nRead-only lookup. All write operations require explicit user confirmation — see ⚠️ markers in reference files.\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task scale\nBefore starting any task, assess its scale — this determines the workflow level.\n\n| Scale | Signals | What to skip |\n|-------|---------|--------------|\n| **tiny** | ≤2 files, no backend/auth/infra, cosmetic or config change | Issue, PR, full work log → use `quick-log.md` instead |\n| **normal** | 3–10 files, one area of the codebase | Issue optional if obvious, PR only if risky |\n| **significant** | backend, auth, infra, API, DB, multi-component, deploy | Nothing — full workflow mandatory |\n\nWhen in doubt — treat as significant.\n\n### Clarification (significant tasks only)\nBefore creating an Issue or branching, ask until requirements are clear:\n- What exactly needs to change and why?\n- Are there affected components, APIs, or dependencies?\n- Any constraints — performance, backward compatibility, deadlines?\n- What does \"done\" look like?\n\n**Do not start implementation until answers are clear.** For tiny/normal tasks — skip this, infer from context.\n\n### Task process\n\n**Tiny task:**\n```\n1. Branch from develop          → git checkout -b fix/short-desc\n2. Atomic commit                → \"fix: description\"\n3. Append to quick-log.md       → date + one line what changed\n4. ⚠️ CONFIRM WITH USER — merge via PR → gh pr merge --squash --delete-branch\n```\n\n**Normal/significant task:**\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n   If CI fails:\n   - Download failed logs                  → gh run view <id> --log-failed\n   - Record cause in work log              → Status.blocked or Notes\n   - Fix, commit (\"fix: resolve CI failure\"), push\n   - Wait for green before proceeding\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description follows the template below\n- **Self-review:** read your own diff one more time — check for hardcoded values, leftover debug statements, missing error handling. Only after this request human review.\n\n**PR description template:**\n```markdown\n## What\nBrief description of the change.\n\n## Why\nCloses #<issue>\n\n## Changes\n- Change 1\n- Change 2\n\n## Testing\n- [ ] Tests pass locally\n- [ ] CI green\n- [ ] Manual check done (if UI)\n```\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n### Scope creep\nIf during implementation something additional is discovered that wasn't in the original Issue:\n- Do **not** expand the current task\n- Complete current task as originally scoped\n- Create a new Issue for the additional work\n- Add a note in the current work log under `Notes`\n\n### Hotfix workflow\nHotfixes are emergency fixes branched from `main`. After merging into `main`, the same fix **must** be merged back into `develop` — otherwise the bug returns in the next release.\n\n```\n1. Branch from main                        → git checkout main && git pull\n                                             git checkout -b hotfix/short-desc\n2. Fix, commit                             → \"fix: description\"\n3. Open PR → main                          → gh pr create --base main --head hotfix/...\n4. Merge into main after approval          → gh pr merge --squash --delete-branch\n5. ⚠️ CONFIRM WITH USER — merge into develop too → git checkout develop && git pull\n                                                    git merge main\n                                                    git push origin develop\n6. Tag the release                         → gh release create vX.Y.Z --target main\n7. Record in work log                      → what broke, what was fixed, why\n```\n\nNever skip step 5 — an unsynced `develop` will reintroduce the bug on next release.\n\n---\n\n## Work Log\n\nEvery task gets a log entry. Format depends on scale.\n\n### Quick log (tiny tasks only)\nOne shared file per project: `work/quick-log.md`\n\n```markdown\n## 2026-05-08\n- fixed listing card spacing (components/Card.css)\n- updated parser timeout (config/parser.yml)\n- corrected Georgian translation (locales/ka.json)\n```\n\nAppend one line per tiny task. No structure, no status, no decisions. Created once, never compacted.\n\n### Full log (normal / significant tasks)\nEvery significant task gets its own log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Never store secrets, tokens, or credentials in work logs\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.5:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.5\",\n  \"publishedAt\": 1778345744786\n}\n\nFile v1.3.5:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.5:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.5:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.5:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.5:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.5:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nFile v1.3.5:skill-card.md\n\n## Description:\n\nGuides agents through GitHub-centered project workflows covering repository setup, branching, commits, pull requests, CI/CD, releases, secrets management, and work logs.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[kretkas](https://clawhub.ai/user/kretkas)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and AI agents use this skill to manage GitHub repositories with consistent branching, pull request, CI, release, secret-handling, and task-continuity practices.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The skill broadly applies a GitHub workflow to coding tasks and may lead an agent to create or change repository artifacts.\n\nMitigation: Install it only for GitHub-centered work, require explicit user approval before branch, commit, issue, pull request, merge, release, secret, workflow, branch-protection, or work-log writes, and avoid enabling it globally for unrelated tasks.\n\nRisk: GitHub authentication and repository secrets are part of the workflow.\n\nMitigation: Use `gh auth status` to verify authentication, set secrets interactively with `gh secret set`, and never print or log tokens, secrets, or credentials.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/kretkas/skills/github-project-workflow)\n- [API Queries, Search & Audit](references/api-queries.md)\n- [CI / GitHub Actions](references/ci-actions.md)\n- [Pull Requests](references/pull-requests.md)\n- [Releases & Versioning](references/releases.md)\n- [Repo Setup & Branch Protection](references/repo-setup.md)\n- [Secrets & Environments](references/secrets-envs.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Shell commands, Configuration]\n\n**Output Format:** [Markdown guidance with inline shell command and configuration examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Includes workflow checklists, confirmation warnings for write operations, and secret-handling guidance.]\n\n## Skill Version(s):\n\n1.3.5 (source: release evidence)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.3.4: 8 files, 10102 bytes\n\nFiles: references/api-queries.md (1433b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (13054b), _meta.json (142b)\n\nFile v1.3.4:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. On any mention of GitHub, git, repo, PR, branch, merge, commit, issue, release, CI, Actions, version, tag, secret, or project setup — use this skill.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n### On every task\n- Assess task scale first (see Task scale table in Agent Workflow).\n- Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge.\n- Normal/significant tasks: Issue and work log are mandatory before branching.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist on normal/significant tasks.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n## Security (always)\n- All operations via `gh` CLI. Always `--repo owner/repo` outside a git directory.\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task scale\nBefore starting any task, assess its scale — this determines the workflow level.\n\n| Scale | Signals | What to skip |\n|-------|---------|--------------|\n| **tiny** | ≤2 files, no backend/auth/infra, cosmetic or config change | Issue, PR, full work log → use `quick-log.md` instead |\n| **normal** | 3–10 files, one area of the codebase | Issue optional if obvious, PR only if risky |\n| **significant** | backend, auth, infra, API, DB, multi-component, deploy | Nothing — full workflow mandatory |\n\nWhen in doubt — treat as significant.\n\n### Clarification (significant tasks only)\nBefore creating an Issue or branching, ask until requirements are clear:\n- What exactly needs to change and why?\n- Are there affected components, APIs, or dependencies?\n- Any constraints — performance, backward compatibility, deadlines?\n- What does \"done\" look like?\n\n**Do not start implementation until answers are clear.** For tiny/normal tasks — skip this, infer from context.\n\n### Task process\n\n**Tiny task:**\n```\n1. Branch from develop          → git checkout -b fix/short-desc\n2. Atomic commit                → \"fix: description\"\n3. Append to quick-log.md       → date + one line what changed\n4. ⚠️ CONFIRM WITH USER — merge via PR → gh pr merge --squash --delete-branch\n```\n\n**Normal/significant task:**\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n   If CI fails:\n   - Download failed logs                  → gh run view <id> --log-failed\n   - Record cause in work log              → Status.blocked or Notes\n   - Fix, commit (\"fix: resolve CI failure\"), push\n   - Wait for green before proceeding\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description follows the template below\n- **Self-review:** read your own diff one more time — check for hardcoded values, leftover debug statements, missing error handling. Only after this request human review.\n\n**PR description template:**\n```markdown\n## What\nBrief description of the change.\n\n## Why\nCloses #<issue>\n\n## Changes\n- Change 1\n- Change 2\n\n## Testing\n- [ ] Tests pass locally\n- [ ] CI green\n- [ ] Manual check done (if UI)\n```\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n### Scope creep\nIf during implementation something additional is discovered that wasn't in the original Issue:\n- Do **not** expand the current task\n- Complete current task as originally scoped\n- Create a new Issue for the additional work\n- Add a note in the current work log under `Notes`\n\n### Hotfix workflow\nHotfixes are emergency fixes branched from `main`. After merging into `main`, the same fix **must** be merged back into `develop` — otherwise the bug returns in the next release.\n\n```\n1. Branch from main                        → git checkout main && git pull\n                                             git checkout -b hotfix/short-desc\n2. Fix, commit                             → \"fix: description\"\n3. Open PR → main                          → gh pr create --base main --head hotfix/...\n4. Merge into main after approval          → gh pr merge --squash --delete-branch\n5. ⚠️ CONFIRM WITH USER — merge into develop too → git checkout develop && git pull\n                                                    git merge main\n                                                    git push origin develop\n6. Tag the release                         → gh release create vX.Y.Z --target main\n7. Record in work log                      → what broke, what was fixed, why\n```\n\nNever skip step 5 — an unsynced `develop` will reintroduce the bug on next release.\n\n---\n\n## Work Log\n\nEvery task gets a log entry. Format depends on scale.\n\n### Quick log (tiny tasks only)\nOne shared file per project: `work/quick-log.md`\n\n```markdown\n## 2026-05-08\n- fixed listing card spacing (components/Card.css)\n- updated parser timeout (config/parser.yml)\n- corrected Georgian translation (locales/ka.json)\n```\n\nAppend one line per tiny task. No structure, no status, no decisions. Created once, never compacted.\n\n### Full log (normal / significant tasks)\nEvery significant task gets its own log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Never store secrets, tokens, or credentials in work logs\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.4:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.4\",\n  \"publishedAt\": 1778196955955\n}\n\nFile v1.3.4:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.4:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.4:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.4:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.4:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.4:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.3.3: 8 files, 9700 bytes\n\nFiles: references/api-queries.md (1499b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (12038b), _meta.json (142b)\n\nFile v1.3.3:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. On any mention of GitHub, git, repo, PR, branch, merge, commit, issue, release, CI, Actions, version, tag, secret, or project setup — use this skill.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n---\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n---\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n---\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n---\n\n### On every task\n- Assess task scale first (see Task scale table in Agent Workflow).\n- Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge.\n- Normal/significant tasks: Issue and work log are mandatory before branching.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist on normal/significant tasks.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n---\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task scale\nBefore starting any task, assess its scale — this determines the workflow level.\n\n| Scale | Signals | What to skip |\n|-------|---------|--------------|\n| **tiny** | ≤2 files, no backend/auth/infra, cosmetic or config change | Issue, PR, full work log → use `quick-log.md` instead |\n| **normal** | 3–10 files, one area of the codebase | Issue optional if obvious, PR only if risky |\n| **significant** | backend, auth, infra, API, DB, multi-component, deploy | Nothing — full workflow mandatory |\n\nWhen in doubt — treat as significant.\n\n### Task process\n\n**Tiny task:**\n```\n1. Branch from develop           → git checkout -b fix/short-desc\n2. Atomic commit                 → \"fix: description\"\n3. Append to quick-log.md        → date + one line what changed\n4. ⚠️ CONFIRM WITH USER — merge via PR  → gh pr merge --squash --delete-branch\n```\n\n**Normal / Significant task:**\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n   If CI fails:\n   - Download failed logs                  → gh run view <id> --log-failed\n   - Record cause in work log              → Status.blocked or Notes\n   - Fix, commit (\"fix: resolve CI failure\"), push\n   - Wait for green before proceeding\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description has \"Closes #<issue>\"\n- **Self-review:** read your own diff one more time — check for hardcoded values, leftover debug statements, missing error handling. Only after this request human review.\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n### Hotfix workflow\nHotfixes are emergency fixes branched from `main`. After merging into `main`, the same fix **must** be merged back into `develop` — otherwise the bug returns in the next release.\n\n```\n1. Branch from main                        → git checkout main && git pull\n                                             git checkout -b hotfix/short-desc\n2. Fix, commit                             → \"fix: description\"\n3. Open PR → main                          → gh pr create --base main --head hotfix/...\n4. Merge into main after approval          → gh pr merge --squash --delete-branch\n5. ⚠️ Immediately merge into develop too   → git checkout develop && git pull\n                                             git merge main\n                                             git push origin develop\n6. Tag the release                         → gh release create vX.Y.Z --target main\n7. Record in work log                      → what broke, what was fixed, why\n```\n\nNever skip step 5 — an unsynced `develop` will reintroduce the bug on next release.\n\n---\n\nEvery task gets a log entry. Format depends on scale.\n\n### Quick log (tiny tasks only)\nOne shared file per project: `work/quick-log.md`\n\n```markdown\n## 2026-05-08\n- fixed listing card spacing (components/Card.css)\n- updated parser timeout (config/parser.yml)\n- corrected Georgian translation (locales/ka.json)\n```\n\nAppend one line per tiny task. No structure, no status, no decisions. Created once, never compacted.\n\n### Full log (normal / significant tasks)\nEvery significant task gets its own log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.3:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.3\",\n  \"publishedAt\": 1778196195236\n}\n\nFile v1.3.3:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\n# ⚠️ CONFIRM WITH USER before running — creates a new issue\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.3:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.3:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.3:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.3:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.3:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.3.2: 8 files, 9209 bytes\n\nFiles: references/api-queries.md (1499b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (10591b), _meta.json (142b)\n\nFile v1.3.2:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. On any mention of GitHub, git, repo, PR, branch, merge, commit, issue, release, CI, Actions, version, tag, secret, or project setup — use this skill.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n---\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n---\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n---\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n---\n\n### On every task\n- Assess task scale first (see Task scale table in Agent Workflow).\n- Tiny tasks: branch → commit → quick-log → merge. No Issue, no PR, no full work log.\n- Normal/significant tasks: Issue and work log are mandatory before branching.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist on normal/significant tasks.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n---\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task scale\nBefore starting any task, assess its scale — this determines the workflow level.\n\n| Scale | Signals | What to skip |\n|-------|---------|--------------|\n| **tiny** | ≤2 files, no backend/auth/infra, cosmetic or config change | Issue, PR, full work log → use `quick-log.md` instead |\n| **normal** | 3–10 files, one area of the codebase | Issue optional if obvious, PR only if risky |\n| **significant** | backend, auth, infra, API, DB, multi-component, deploy | Nothing — full workflow mandatory |\n\nWhen in doubt — treat as significant.\n\n### Task process\n\n**Tiny task:**\n```\n1. Branch from develop           → git checkout -b fix/short-desc\n2. Atomic commit                 → \"fix: description\"\n3. Append to quick-log.md        → date + one line what changed\n4. Push + merge directly         → gh pr merge --squash --delete-branch (or direct push to develop if protected=false)\n```\n\n**Normal / Significant task:**\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description has \"Closes #<issue>\"\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n---\n\n## Work Log\n\nEvery task gets a log entry. Format depends on scale.\n\n### Quick log (tiny tasks only)\nOne shared file per project: `work/quick-log.md`\n\n```markdown\n## 2026-05-08\n- fixed listing card spacing (components/Card.css)\n- updated parser timeout (config/parser.yml)\n- corrected Georgian translation (locales/ka.json)\n```\n\nAppend one line per tiny task. No structure, no status, no decisions. Created once, never compacted.\n\n### Full log (normal / significant tasks)\nEvery significant task gets its own log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.2:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.2\",\n  \"publishedAt\": 1778194668782\n}\n\nFile v1.3.2:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\n# ⚠️ CONFIRM WITH USER before running — creates a new issue\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.2:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.2:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.2:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.2:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.2:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.3.1: 8 files, 8636 bytes\n\nFiles: references/api-queries.md (1499b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (9201b), _meta.json (142b)\n\nFile v1.3.1:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. Use this skill for ANY software development, coding task, bug fix, feature implementation, or project work, even if GitHub or git are not explicitly mentioned. If the user asks to write code, modify files in a project, or fix an error — trigger this workflow.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n---\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n---\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n---\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n---\n\n### On every task\n- Every task must have an Issue. If there is none — create one before branching.\n- Every task must have a work log file in `work/`. Create it immediately after the Issue.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n---\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task process\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description has \"Closes #<issue>\"\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n---\n\n## Work Log\n\nEvery task gets a log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.1:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.1\",\n  \"publishedAt\": 1778179210494\n}\n\nFile v1.3.1:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\n# ⚠️ CONFIRM WITH USER before running — creates a new issue\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.1:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.1:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.1:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.1:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.1:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.3.0: 8 files, 8594 bytes\n\nFiles: references/api-queries.md (1499b), references/ci-actions.md (1318b), references/pull-requests.md (1445b), references/releases.md (1625b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (9091b), _meta.json (142b)\n\nFile v1.3.0:SKILL.md\n\n---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. On any mention of GitHub, git, repo, PR, branch, merge, commit, issue, release, CI, Actions, version, tag, secret, or project setup — use this skill.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n---\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n---\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n---\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n---\n\n### On every task\n- Every task must have an Issue. If there is none — create one before branching.\n- Every task must have a work log file in `work/`. Create it immediately after the Issue.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n---\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## Agent Workflow\n\n### Workspace layout\nAlways clone into `~/workspace/projects/<repo-name>/`. Never work in `/tmp` — it doesn't persist between sessions.\n\n```bash\nmkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name\n```\n\n### Session start (every time)\n```bash\ngh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next\n```\n\n### Task process\n```\n1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42\n```\n\n### Pre-PR checklist\nBefore marking PR ready:\n- Run tests locally\n- `git diff origin/develop` — no debug code, credentials, or temp files\n- CI is green (`gh pr checks <n>`)\n- PR description has \"Closes #<issue>\"\n\n### Between sessions\nIf a task is unfinished at end of session:\n```bash\ngit stash push -m \"wip: description of what's in progress\"\n```\nUpdate `Status` and `next` in the work log, then stop. On next session: read `next`, then `git stash pop`.\n\n### Merge conflicts\nWhen a conflict occurs during merge or rebase:\n```bash\ngit status                         # see conflicted files\n# Open each file — resolve manually, keep correct code\ngit add <resolved-file>\ngit rebase --continue              # or git merge --continue\n\n# If too complex — abort and ask the user\ngit rebase --abort\ngit merge --abort\n```\nRules:\n- Never blindly accept `--ours` or `--theirs` without understanding the diff\n- If unsure which change is correct — **stop and ask the user**\n- After resolving, re-run tests before pushing\n\n---\n\n## Work Log\n\nEvery task gets a log file. It is the agent's memory — orientation, decisions, state.\n\n### Setup\n```bash\nmkdir -p work\n# Add to .gitignore once per project\necho \"work/\" >> .gitignore\n```\nFile: `work/<issue-number>-<short-desc>.md`\n\n### Structure\n```markdown\n# Task: <title> (#<issue>)\nGoal: <one sentence — what \"done\" means>\n\n## Status\ncurrent: <what agent is doing right now>\nnext: <planned next action>\nblocked: <blocker or —>\n\n## Done\n- [x] Created branch feature/42-user-auth\n- [x] Added JWT middleware (src/auth.js)\n- [ ] PR review pending\n\n## Decisions\n- Used HS256 — no key infrastructure in this project\n- Skipped refresh token — out of scope per Issue comment\n\n## Notes\n- src/auth.js:84 — edge case when token is exactly expired, needs attention\n- AUTH_SECRET env var must be added to secrets before deploy\n```\n\n### When to write\n\n| Event | Action |\n|-------|--------|\n| Session start | Read `next`, update `current` |\n| File or module created | Add to `Done` |\n| Decision made | Add to `Decisions` with reason |\n| Unexpected finding | Add to `Notes` |\n| Step completed | Check off `Done`, update `next` |\n| Session end | Update `Status`, write `next` explicitly |\n| Task complete | Compact, then archive |\n\n### Compacting\nCompact when file exceeds ~80 lines **or** when task is complete.\n- `Done` — keep unchecked + last 3 completed, drop the rest\n- `Decisions` — keep all, never delete\n- `Notes` — drop resolved, keep open\n- `Status` — rewrite fresh\n\n### Rules\n- Always update `next` before ending a session — it is the re-entry point\n- Never delete `Decisions` — they prevent re-debating solved problems\n- Compact proactively — a bloated log defeats the purpose\n\n---\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1778178575344\n}\n\nFile v1.3.0:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\n# ⚠️ CONFIRM WITH USER before running — creates a new issue\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.3.0:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```\n\nFile v1.3.0:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```\n\nFile v1.3.0:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — creates a draft release (not yet public)\ngh release create v1.3.0 --repo owner/repo --draft \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\"\n\n# ⚠️ CONFIRM WITH USER before running — publishes a release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — edits an existing release (title, notes, draft status)\ngh release edit v1.3.0 --repo owner/repo --notes \"Updated changelog\"\ngh release edit v1.3.0 --repo owner/repo --draft=false  # publish a draft release\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.3.0:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.3.0:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.2.0: 8 files, 5450 bytes\n\nFiles: references/api-queries.md (1499b), references/ci-actions.md (1043b), references/pull-requests.md (1183b), references/releases.md (1111b), references/repo-setup.md (1079b), references/secrets-envs.md (998b), SKILL.md (2241b), _meta.json (142b)\n\nFile v1.2.0:SKILL.md\n\n---\nname: github\ndescription: \"Professional GitHub workflows via gh CLI. Use for repos, branches, PRs, CI/CD, releases, versioning, secrets, issues. Trigger on: GitHub, git, repo, PR, branch, merge, release, CI, Actions, issue, tag, version.\"\n---\n\n# GitHub Skill\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1778109896209\n}\n\nFile v1.2.0:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\n# ⚠️ CONFIRM WITH USER before running — creates a new issue\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.2.0:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n\nFile v1.2.0:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\nFile v1.2.0:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — publishes a new release to the repository\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\n# ⚠️ CONFIRM WITH USER before running — publishes a pre-release (visible to all)\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes the release\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\n# ⚠️ CONFIRM WITH USER before running — pushes a tag to remote\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.2.0:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\n\n# ⚠️ CONFIRM WITH USER before running — makes repo read-only permanently\ngh repo archive owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — permanently deletes repo and all data\ngh repo delete owner/repo --yes\n```\n\n## Branch Protection (main & develop)\n```bash\n# ⚠️ CONFIRM WITH USER before running — changes who can push/merge to the branch\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.2.0:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret to the repository\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\n\n# ⚠️ CONFIRM WITH USER before running — writes a secret scoped to an environment\ngh secret set API_KEY --repo owner/repo --env production\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# ⚠️ CONFIRM WITH USER before running — creates or overwrites environment protection rules\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — sets a repository variable\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```\n\nArchive v1.1.0: 8 files, 4892 bytes\n\nFiles: references/api-queries.md (1290b), references/ci-actions.md (749b), references/pull-requests.md (1081b), references/releases.md (788b), references/repo-setup.md (895b), references/secrets-envs.md (727b), SKILL.md (2240b), _meta.json (142b)\n\nFile v1.1.0:SKILL.md\n\n---\nname: github\ndescription: \"Professional GitHub workflows via gh CLI. Use for repos, branches, PRs, CI/CD, releases, versioning, secrets, issues. Trigger on: GitHub, git, repo, PR, branch, merge, release, CI, Actions, issue, tag, version.\"\n---\n\n# GitHub Skill\n\n`gh` CLI for all operations. Always `--repo owner/repo` outside a git directory.\n\n## Security (always)\n- Auth: `gh auth login --web` or `GITHUB_TOKEN` env var\n- Secrets: `gh secret set NAME --repo owner/repo` (interactive, never `--body`)\n- Never print/log tokens. `gh auth status` to verify.\n\n## Quick Reference\n\n| Task | Command |\n|------|---------|\n| Auth check | `gh auth status` |\n| List PRs | `gh pr list --repo o/r` |\n| Create PR | `gh pr create --repo o/r --title \"...\" --base develop --head branch` |\n| PR checks | `gh pr checks <n> --repo o/r` |\n| Merge (squash) | `gh pr merge <n> --squash --delete-branch --repo o/r` |\n| Failed CI logs | `gh run view <id> --log-failed --repo o/r` |\n| Re-run failed | `gh run rerun <id> --failed-only --repo o/r` |\n| Create issue | `gh issue create --repo o/r --title \"...\" --body \"...\"` |\n| Create release | `gh release create vX.Y.Z --repo o/r --title \"...\" --notes \"...\"` |\n| Set secret | `gh secret set KEY --repo o/r` |\n| Branch protect | `gh api --method PUT repos/o/r/branches/main/protection ...` |\n\n## Branching Model\n```\nmain       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\n```\nCommit convention: `feat: description (#42)` / `fix: description (#42)`\nPR merge: `--squash` for features, `--merge` for releases.\nSemver: `MAJOR.MINOR.PATCH` — breaking/feature/fix.\n\n## When to read reference files\n\nLoad only what you need for the current task:\n\n| Task | Read |\n|------|------|\n| Setting up a new repo, branch protection | `references/repo-setup.md` |\n| PRs, reviews, merge strategies | `references/pull-requests.md` |\n| CI runs, GitHub Actions | `references/ci-actions.md` |\n| Releases, versioning, tags | `references/releases.md` |\n| Secrets, environments | `references/secrets-envs.md` |\n| JSON queries, audit, search | `references/api-queries.md` |\n\nFile v1.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.1.0\",\n  \"publishedAt\": 1778109455738\n}\n\nFile v1.1.0:references/api-queries.md\n\n# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\ngh issue close 42 --repo owner/repo\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```\n\nFile v1.1.0:references/ci-actions.md\n\n# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\ngh workflow enable deploy.yml --repo owner/repo\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n\nFile v1.1.0:references/pull-requests.md\n\n# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\nFile v1.1.0:references/releases.md\n\n# Releases & Versioning\n\n## Semver: MAJOR.MINOR.PATCH\n- MAJOR — breaking change (1.x → 2.0.0)\n- MINOR — new feature, backward compatible (1.2.x → 1.3.0)\n- PATCH — bug fix (1.2.3 → 1.2.4)\n\n## Commands\n```bash\ngh release list --repo owner/repo\n\ngh release create v1.3.0 --repo owner/repo \\\n  --title \"v1.3.0 — feature name\" \\\n  --notes \"## What's New\\n- feat (#55)\\n\\n## Fixes\\n- fix (#61)\\n\\n## Breaking\\nNone\" \\\n  --target main\n\ngh release create v2.0.0-rc.1 --repo owner/repo --prerelease\n\ngh release upload v1.3.0 ./dist/binary --repo owner/repo  # attach artifact\n\ngh release delete v1.3.0 --repo owner/repo --yes\n```\n\n## Tags\n```bash\ngit tag v1.3.0 && git push origin v1.3.0\ngh api repos/owner/repo/git/refs --jq '.[] | select(.ref | startswith(\"refs/tags\")) | .ref'\n```\n\nFile v1.1.0:references/repo-setup.md\n\n# Repo Setup & Branch Protection\n\n## Create / Clone / Fork\n```bash\ngh repo create owner/repo --private --description \"...\"\ngh repo create owner/repo --public --gitignore Node --license MIT\ngh repo clone owner/repo\ngh repo fork owner/repo --clone\ngh repo view owner/repo --json name,description,defaultBranch,isPrivate\ngh repo archive owner/repo\ngh repo delete owner/repo --yes   # irreversible\n```\n\n## Branch Protection (main & develop)\n```bash\n# Full protection: require PR + 1 review + CI green\ngh api --method PUT repos/owner/repo/branches/main/protection \\\n  --field required_status_checks='{\"strict\":true,\"contexts\":[\"ci/tests\"]}' \\\n  --field enforce_admins=true \\\n  --field required_pull_request_reviews='{\"required_approving_review_count\":1}' \\\n  --field required_linear_history=true \\\n  --field restrictions=null\n\n# View current rules\ngh api repos/owner/repo/branches/main/protection\n```\n\nFile v1.1.0:references/secrets-envs.md\n\n# Secrets & Environments\n\n## Secrets\n```bash\ngh secret list --repo owner/repo                          # names only, values never shown\ngh secret set DATABASE_URL --repo owner/repo              # interactive (safest)\ngh secret set API_KEY --repo owner/repo --env production  # env-scoped\n```\n\n## Environments\n```bash\ngh api repos/owner/repo/environments --jq '.environments[].name'\n\n# Create with protection (manual approval + 10min wait)\ngh api --method PUT repos/owner/repo/environments/production \\\n  --field wait_timer=10 \\\n  --field reviewers='[{\"type\":\"User\",\"id\":USER_ID}]'\n```\n\n## Variables (non-secret config)\n```bash\ngh variable list --repo owner/repo\ngh variable set APP_ENV --body \"production\" --repo owner/repo\n```","readmeExcerpt":"Skill: GitHub Workflow Owner: kretkas Summary: Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review,... Tags: latest:1.3.5 Version history: v1.3.5 | 2026-05-09T16:55:44.786Z | user github-project-workflow 1.3.5 - Updated trigger instructions in the skill description for clarity; now lists more specific keywords incl","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"main       ← production, protected\ndevelop    ← integration\nfeature/*  ← from develop\nfix/*      ← from develop (reference issue: fix/123-desc)\nhotfix/*   ← from main (emergency)\nrelease/*  ← from develop (prep)\nchore/*    ← from develop (deps, tooling, CI — no product change)"},{"language":"bash","snippet":"mkdir -p ~/workspace/projects\ngh repo clone owner/repo ~/workspace/projects/repo-name\ncd ~/workspace/projects/repo-name"},{"language":"bash","snippet":"gh auth status                   # 1. verify auth\ngit checkout develop && git pull # 2. sync before any work\ngit branch                       # 3. confirm you're on the right branch\n# 4. open work/<issue>-<desc>.md and read Status.next"},{"language":"text","snippet":"1. Branch from develop          → git checkout -b fix/short-desc\n2. Atomic commit                → \"fix: description\"\n3. Append to quick-log.md       → date + one line what changed\n4. ⚠️ CONFIRM WITH USER — merge via PR → gh pr merge --squash --delete-branch"},{"language":"text","snippet":"1. Create or find the Issue                → gh issue create / gh issue list\n2. Create work log file                    → work/<issue>-<desc>.md (see Work Log section below)\n3. Branch from develop                     → git checkout -b feature/42-short-desc\n4. Make small atomic commits               → one change per commit\n5. Commit message references Issue         → \"feat: description (#42)\"\n6. Open draft PR after first commit        → gh pr create --draft (signals work in progress early)\n7. Monitor CI                              → gh run watch\n   If CI fails:\n   - Download failed logs                  → gh run view <id> --log-failed\n   - Record cause in work log              → Status.blocked or Notes\n   - Fix, commit (\"fix: resolve CI failure\"), push\n   - Wait for green before proceeding\n8. Pre-PR checklist (see below)\n9. Mark ready + request review             → gh pr ready / gh pr review\n10. Merge after approval                   → gh pr merge --squash --delete-branch\n11. Close Issue + compact work log         → gh issue close 42"},{"language":"markdown","snippet":"## What\nBrief description of the change.\n\n## Why\nCloses #<issue>\n\n## Changes\n- Change 1\n- Change 2\n\n## Testing\n- [ ] Tests pass locally\n- [ ] CI green\n- [ ] Manual check done (if UI)"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: GitHub Workflow\ndescription: \"Professional GitHub workflow skill for AI agents. Covers full project lifecycle: repo setup, Git Flow branching, atomic commits, pull requests, code review, CI/CD monitoring, semantic versioning, releases, secrets management, and security rules. Includes mandatory agent behavior directives for skill installation, new projects, and returning to existing work. Features built-in work log system for task state and session continuity. Trigger on: GitHub, git, gh CLI, repo, PR, branch, merge, commit, issue, release, CI, GitHub Actions, tag, secret.\"\n---\n\n# GitHub Skill\n\n## Agent Directives\n\nThese are mandatory behavioral rules. Follow them in every situation involving code, projects, or tasks.\n\n### On skill installation\nWhen this skill is first loaded, introduce it to the user:\n- Explain that all project work will now follow a professional GitHub workflow\n- Mention: branching strategy, work logs, CI checks, semantic versioning, security rules\n- Ask: \"Do you have an existing project, or are we starting a new one?\"\n\n### On new project\n**If this is the user's first project ever:**\n- Check `gh auth status` — if not authenticated, run `gh auth login --web` before anything else\n- Offer to create a new repo: name, visibility (public/private), license, .gitignore\n- Set up branch protection on `main` and `develop` right away\n- Clone into `~/workspace/projects/<repo-name>/`\n- Create initial `develop` branch\n- Confirm setup is complete before starting any work\n\n**If the user already has projects:**\n- Ask which repo they want to work on, or detect from context\n- Clone into `~/workspace/projects/<repo-name>/` if not already there\n- Verify branch protection is in place — if not, offer to set it up\n- Proceed directly to task workflow\n\n### On continuing existing work\nWhen the user returns to an already-cloned project — run the Session start checklist (see Agent Workflow below) before making any changes.\n\n### On every task\n- Assess task scale first (see Task scale table in Agent Workflow).\n- Tiny tasks: branch → commit → quick-log → PR → confirm with user → merge.\n- Normal/significant tasks: Issue and work log are mandatory before branching.\n- Never commit directly to `main` or `develop`.\n- Never skip the pre-PR checklist on normal/significant tasks.\n- Never expose tokens, secrets, or credentials in any command or output.\n- If something is irreversible (delete, merge, release, force push) — **always confirm with the user first**.\n\n### On using this skill\n- This file (SKILL.md) is always in context — use it for workflow, branching, work log rules.\n- Reference files are loaded **on demand only** — read them when the task requires it, not upfront.\n- Work log is not optional — it is part of every task from start to finish.\n- When in doubt about a GitHub operation — check the relevant reference file before acting.\n\n---\n\n## Security (always)\n- All operations via `gh` CLI. Always `--repo owner/repo` outside a git directory.\n- Auth: `gh "},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn71braj4mtw6xbr2sbydm0p6s866qsx\",\n  \"slug\": \"github-project-workflow\",\n  \"version\": \"1.3.5\",\n  \"publishedAt\": 1778345744786\n}"},{"path":"references/api-queries.md","content":"# API Queries, Search & Audit\n\n## Issues\n```bash\ngh issue list --repo owner/repo --label \"bug\" --state open\ngh issue list --repo owner/repo --assignee \"@me\"\n\ngh issue create --repo owner/repo --title \"...\" --body \"...\" --label \"bug\"\n\n# ⚠️ CONFIRM WITH USER before running — posts a comment on the issue\ngh issue comment 42 --repo owner/repo --body \"Fixed in #55, released in v1.2.1\"\n\n# ⚠️ CONFIRM WITH USER before running — closes the issue\ngh issue close 42 --repo owner/repo\n\n# In commits always: \"fixes #42\" / \"closes #42\" / \"resolves #42\"\n```\n\n## JSON queries\n```bash\ngh pr list --repo owner/repo \\\n  --json number,title,state,mergeable,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.state)]\"'\n\ngh issue list --repo owner/repo \\\n  --json number,title,labels \\\n  --jq '.[] | \"\\(.number): \\(.title) | \\([.labels[].name]|join(\",\"))\"'\n\ngh api repos/owner/repo/issues --paginate --jq '.[].title'\n```\n\n## Audit\n```bash\n# Recent commits\ngh api repos/owner/repo/commits \\\n  --jq '.[:10][] | \"\\(.sha[:7]) \\(.commit.author.name): \\(.commit.message|split(\"\\n\")[0])\"'\n\n# PR for a commit\ngh api repos/owner/repo/commits/<sha>/pulls --jq '.[0]|\"#\\(.number) \\(.title)\"'\n\n# Search TODOs\ngh api search/code --field q=\"TODO repo:owner/repo\" \\\n  --jq '.items[] | \"\\(.path): \\(.text_matches[0].fragment)\"'\n\n# Repo stats\ngh api repos/owner/repo --jq '{stars:.stargazers_count,forks:.forks_count,issues:.open_issues_count}'\n```"},{"path":"references/ci-actions.md","content":"# CI / GitHub Actions\n\n## Runs\n```bash\ngh run list --repo owner/repo --limit 10\ngh run watch --repo owner/repo\ngh run view <id> --repo owner/repo --log-failed\ngh run rerun <id> --repo owner/repo --failed-only\ngh run rerun <id> --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — cancels an active run\ngh run cancel <id> --repo owner/repo\n```\n\n## Workflows\n```bash\ngh workflow list --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — triggers a workflow run (may deploy or modify infra)\ngh workflow run deploy.yml --repo owner/repo --field environment=staging\n\n# ⚠️ CONFIRM WITH USER before running — enables a workflow (it will start running on triggers)\ngh workflow enable deploy.yml --repo owner/repo\n\n# ⚠️ CONFIRM WITH USER before running — disables a workflow (stops all future runs)\ngh workflow disable deploy.yml --repo owner/repo\n```\n\n## Checklist for .github/workflows/\n- Pin actions to SHA (not `@latest`)\n- Use `${{ secrets.GITHUB_TOKEN }}` — never hardcode\n- Cache deps: `actions/cache`\n- Tests on every PR; deploy only on merge to main\n- Use `environments:` with required reviewers for production\n- Always declare `permissions:` explicitly — default is too broad\n\n```yaml\n# Minimal safe permissions example\npermissions:\n  contents: read\n  pull-requests: write\n```"},{"path":"references/pull-requests.md","content":"# Pull Requests\n\n## Create\n```bash\ngh pr create --repo owner/repo \\\n  --title \"feat: description (#42)\" \\\n  --body \"## What\\n...\\n## Why\\nCloses #42\\n## Testing\\n- [ ] tests pass\" \\\n  --base develop --head feature/branch \\\n  --label \"feature\" --assignee \"@me\"\n\ngh pr create ... --draft          # WIP\ngh pr ready 55 --repo owner/repo  # promote draft\n```\n\n## Review & Inspect\n```bash\ngh pr view 55 --repo owner/repo\ngh pr diff 55 --repo owner/repo\ngh pr checks 55 --repo owner/repo\ngh pr review 55 --approve --body \"LGTM\"\ngh pr review 55 --request-changes --body \"...\"\ngh pr comment 55 --body \"...\"\n```\n\n## Merge strategies\n```bash\n# ⚠️ CONFIRM WITH USER before running — merges code into base branch and deletes source branch\ngh pr merge 55 --squash --delete-branch --repo owner/repo  # features (clean history)\ngh pr merge 55 --merge --repo owner/repo                   # releases (preserve history)\ngh pr merge 55 --rebase --delete-branch --repo owner/repo  # linear history\n```\n\n## List\n```bash\ngh pr list --repo owner/repo\ngh pr list --repo owner/repo --assignee \"@me\"\ngh pr list --repo owner/repo --json number,title,state,reviewDecision \\\n  --jq '.[] | \"\\(.number): \\(.title) [\\(.reviewDecision // \"pending\")]\"'\n```\n\n## Close without merging\n```bash\n# ⚠️ CONFIRM WITH USER before running — closes PR without merging (task cancelled or superseded)\ngh pr close 55 --repo owner/repo --comment \"Closing — superseded by #60\"\n```"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1491,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T02:54:32.811Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T05:28:11.015Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}