GitHub Bot

SkillDev tools

Interact with the GitHub API as the joelclawgithub[bot] app. Use when creating PRs, pushing commits, managing issues, checking CI status, listing repos, or any GitHub API operation. Triggers on "create a PR", "push to GitHub", "open an issue", "check CI", "list repos", "merge PR", "GitHub API", or any task requiring programmatic GitHub access. All actions appear as joelclawgithub[bot], not as @joelhooks.

Available today. Use it from your connected AI after setup.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the GitHub Bot skill

What this skill tells your AI

The instructions your AI receives, as published by joelhooks/joelclaw in skills/github-bot/SKILL.md and read by ahel’s review.

For ShitRat-authored work, use the installed shitrat tooling and shitratgit[bot] identity. The legacy app described below is for integrations that explicitly own it, not a default actor for Joel’s agent-authored commits, PRs, or comments. Discover actual app access; old repository counts are not authority.

Interact with GitHub API via the joelclawgithub[bot] GitHub App. Acts as a bot identity with access to all 280+ repos across @joelhooks personal and org accounts.

Authentication

Generate a 1-hour installation token:

TOKEN=$(SKILL_DIR/scripts/github-token.sh)

Use in API calls:

curl -H "Authorization: token $TOKEN" -H "Accept: application/vnd.github+json" \
  https://api.github.com/repos/OWNER/REPO/...

Token expires in 1 hour. Generate a new one if a request returns 401.

Secrets

Stored in agent-secrets (do not hardcode):

SecretContent
github_app_idApp ID (2867136)
github_app_client_idClient ID
github_app_installation_idInstallation ID
github_app_pemRSA private key

Bot Identity

  • Commits: joelclawgithub[bot] <2867136+joelclawgithub[bot]@users.noreply.github.com>
  • All API actions (comments, reviews, PRs) show as joelclawgithub[bot]
  • Has read/write access to: contents, issues, PRs, actions, deployments, environments, secrets, packages, workflows, checks, statuses, hooks, projects

Receipts

Use the verified GitHub URL, identifier, commit SHA, or API response as the write receipt. Emit canonical OTel when the calling workflow supports it, and capture durable decisions in Brain .svx. The former slog journal is retired; do not recreate it.

Relevant actions include create-pr, push-commit, create-issue, merge-pr, create-release, and update-workflow.

Pagination

GitHub API paginates at 100 items. For full listing:

PAGE=1
while true; do
  RESULT=$(curl -s -H "Authorization: token $TOKEN" \
    "https://api.github.com/endpoint?per_page=100&page=$PAGE")
  # process $RESULT
  [ "$(echo "$RESULT" | python3 -c 'import json,sys; print(len(json.load(sys.stdin)))')" -lt 100 ] && break
  PAGE=$((PAGE+1))
done

Signals

GitHub stars
64
Forks
2
Last commit
Sep 2026

ahel review

  • S4info
    community integration, published by joelhooks, not github
  • K2info
    exfiltration

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
github-bot
Source
github.com/joelhooks/joelclaw