gh-cli
SkillSecuritySteers your agent to use authenticated GitHub CLI commands instead of unauthenticated web requests when working with GitHub.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the gh-cli skill
About this capability
Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues.
What this skill tells your AI
The instructions your AI receives, as published by trailofbits/skills in plugins/gh-cli/skills/gh-cli/SKILL.md and read by ahel’s review.
When to Use
- Working with GitHub repositories, pull requests, issues, releases, or raw file URLs.
- You need authenticated access to private repositories or higher API rate limits.
- You are about to use
curl,wget,WebFetch, or an MCP fetch tool against GitHub.
When NOT to Use
- The target is not GitHub.
- Plain local git operations already solve the task.
Guidance
Prefer the authenticated gh CLI over raw HTTP fetches for GitHub content. In particular:
- Prefer
gh repo view,gh pr view,gh pr list,gh issue view, andgh apiover unauthenticatedcurlorwget. - Prefer cloning a repository and reading files locally over fetching
raw.githubusercontent.comblobs directly. - Avoid using GitHub API
/contents/endpoints as a substitute for cloning and reading repository files.
Examples:
gh repo view owner/repo
gh pr view 123 --repo owner/repo
gh api repos/owner/repo/pulls
For the hook implementation, see:
plugins/gh-cli/README.mdplugins/gh-cli/hooks/
Signals
- GitHub stars
- 7k
- Forks
- 604
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
gh-cli-trailofbits- Source
- github.com/trailofbits/skills