gh-cli

SkillSecurity

Steers your agent to use authenticated GitHub CLI commands instead of unauthenticated web requests when working with GitHub.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the gh-cli skill

About this capability

Enforces authenticated gh CLI workflows over unauthenticated curl, WebFetch, and MCP fetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues.

What this skill tells your AI

The instructions your AI receives, as published by trailofbits/skills in plugins/gh-cli/skills/gh-cli/SKILL.md and read by ahel’s review.

When to Use

  • Working with GitHub repositories, pull requests, issues, releases, or raw file URLs.
  • You need authenticated access to private repositories or higher API rate limits.
  • You are about to use curl, wget, WebFetch, or an MCP fetch tool against GitHub.

When NOT to Use

  • The target is not GitHub.
  • Plain local git operations already solve the task.

Guidance

Prefer the authenticated gh CLI over raw HTTP fetches for GitHub content. In particular:

  • Prefer gh repo view, gh pr view, gh pr list, gh issue view, and gh api over unauthenticated curl or wget.
  • Prefer cloning a repository and reading files locally over fetching raw.githubusercontent.com blobs directly.
  • Avoid using GitHub API /contents/ endpoints as a substitute for cloning and reading repository files.

Examples:

gh repo view owner/repo
gh pr view 123 --repo owner/repo
gh api repos/owner/repo/pulls

For the hook implementation, see:

  • plugins/gh-cli/README.md
  • plugins/gh-cli/hooks/

Signals

GitHub stars
7k
Forks
604
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
gh-cli-trailofbits
Source
github.com/trailofbits/skills