Review PR Comments
latitude-dev/latitude-llm
Triages a PR with GitHub CLI: loads issue-level and inline review feedback (gh pr view, gh api REST, gh api graphql as appropriate), walks items in order, replies in the correct thread, optional…
Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback.
$ npx skills add daymade/claude-code-skills --skill github-ops -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install daymade/claude-code-skills github-ops --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/github-ops .claude/skills/github-ops && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .claude/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/daymade/claude-code-skills/tree/main/github-opsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add daymade/claude-code-skills --skill github-ops -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install daymade/claude-code-skills github-ops --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/github-ops .agents/skills/github-ops && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .agents/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill github-ops -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install daymade/claude-code-skills github-ops --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/github-ops .cursor/skills/github-ops && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .cursor/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/daymade/claude-code-skills.git --path github-ops--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add daymade/claude-code-skills --skill github-ops -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install daymade/claude-code-skills github-ops --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/github-ops .gemini/skills/github-ops && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .gemini/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install daymade/claude-code-skills github-opsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add daymade/claude-code-skills --skill github-ops -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/github-ops .github/skills/github-ops && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .github/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add daymade/claude-code-skills --skill github-ops -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install daymade/claude-code-skills github-ops --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/daymade/claude-code-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/github-ops .opencode/skills/github-ops && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-ops" agent skill from https://github.com/daymade/claude-code-skills/tree/main/github-ops into .opencode/skills/github-ops/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-ops", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-opsOperates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback.
GitHub Ops is an agent skill from daymade/claude-code-skills. Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback. Use when a write reports success but state didn't change, or choosing gh/REST/GraphQL/UI-only. Not for local Git recovery (use git-safety-net), maintainer PR review (use github-review-pr), or upstream contribution (use github-contributor).
Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 13 other files, including scripts and reference files (for example `references/api_reference.md`, `references/best_practices.md` and `references/branch_protection.md`).
It sits in Backend & APIs, covering Pull requests and GraphQL. It works with GitHub, GraphQL and Git. The repository describes itself as: Professional Claude Code skills marketplace featuring production-ready skills for enhanced development workflows. The licence is MIT.
8 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 91bed2b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
ghuvFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use gh and uv, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Ops loads about 3.8k tokens when it runs, and up to ~35k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 1,717 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from daymade/claude-code-skills at commit 91bed2b, republished under its MIT licence (© daymade). 1,717 words, ~3,775 tokens.
.claude/skills/github-ops/SKILL.md (or your agent's skills folder). This skill also uses 11 other files; get the full folder from GitHub.Deliver the requested GitHub state, not a successful-looking command. A 200, 201,
202, or 204 response is evidence that GitHub accepted a request; it is not proof
that every requested field changed, an invitation was accepted, an asynchronous job
finished, or the user's business outcome was achieved.
Read only the reference required for the task:
| Task | Reference |
|---|---|
| Create, review, merge, close, compare, or converge PRs; clear approved PR body revisions; retire remote PR branches | references/pr_operations.md |
| Create, edit, search, transfer, close, or bulk-manage issues | references/issue_operations.md |
| Inspect, clone, create, edit, rename, archive, transfer, change visibility, or delete repositories | references/repository_operations.md |
| Copy repositories accessible to another account while keeping the usual account active; configure private copies and upstream sync | references/multi_account_repository_sync.md |
| Inspect or change collaborators, teams, base permissions, member privileges, or organization 2FA | references/organization_access_and_settings.md |
| Protect a default branch while letting collaborators contribute through PRs; inventory protection gaps across an account, roll a baseline out to many repositories, and verify enforcement with a real push | references/branch_protection.md |
| Trigger, inspect, rerun, cancel, or purge Actions; manage secrets or variables | references/workflow_operations.md |
| Build and publish a Docker/OCI image to GitHub Container Registry (GHCR) | references/ghcr_publishing.md |
| Use raw REST/GraphQL endpoints, pagination, rate limits, webhooks, or Enterprise hosts | references/api_reference.md |
| Build scripts, retries, bulk operations, or machine-readable output | references/best_practices.md |
For local Git recovery, dirty worktrees, bundles, or lost commits, use git-safety-net.
This skill owns GitHub-hosted state.
For repository copies, also handle per-remote authentication and sync setup.
Do not turn a read-only investigation into a mutation because the fix looks obvious. Do not send a comment, review, issue, or invitation whose recipient or content was not authorized in the current task.
For an authorized contributor, assess repository access against their ongoing contribution role, not just today's read or sync command. Repository Write access and permission to update the default branch are separate decisions. Follow the user's chosen contribution scope; use branch protection and PR review to control integration rather than silently reducing a contributor to Read. A diagnosis alone still does not authorize a grant.
Before the first write, verify the active account and resolve a fully qualified target:
gh auth status --hostname HOST
gh api --hostname HOST user --jq '.login'
gh repo view HOST/OWNER/REPO \
--json nameWithOwner,visibility,isPrivate,viewerPermission,urlFor github.com, OWNER/REPO is sufficient. Never use gh auth status --show-token
for routine diagnosis, and never print, paste, or log a token.
Before the first push to a remote in the current session, read its live visibility:
gh repo view OWNER/REPO \
--json nameWithOwner,visibility,isPrivate,stargazerCount,forkCount,urlBind identity to the interface that will perform the write. CLI identity does not establish a connector, browser, REST client, or Git SSH identity. Resolve the expected actor from the user's authorized task; neither the repository owner nor an available credential selects that actor automatically. For connectors, use a read-only current-user operation from that same connector and confirm its actor. If that interface cannot expose the actor, use the already verified CLI channel for the authorized write; do not make a test comment to discover its identity.
For authorized gh API/hosted-state writes, use the bundled checked invocation.
Resolve <github-ops-dir> to the directory containing this SKILL.md; run the
helper by that path from the task's working directory. Its executable argument
and rejection contract is checked_gh.py.
uv run python <github-ops-dir>/scripts/checked_gh.py --expected-login <EXPECTED_LOGIN> --host HOST
uv run python <github-ops-dir>/scripts/checked_gh.py --expected-login <EXPECTED_LOGIN> --host HOST -- pr edit <NUMBER> -R OWNER/REPO --title '<AUTHORIZED_TITLE>'The first command is read-only. The second resolves the current credential,
checks GET /user, and pins that same credential for one command. A mismatch or
unknown actor exits before execution. It guards only gh, not connector calls,
browser actions or Git pushes. Authentication/configuration commands are rejected;
task authorization, exact targets and independent readback remain required.
Supply -R OWNER/REPO for repository-scoped commands, or an explicit repository
operand for gh repo. The wrapper qualifies that target with the checked host,
removes inherited GH_REPO and alternate token variables from the child, and
rejects conflicting host operands. Omit the command for an identity-only read.
Organization secret/variable operations instead use their explicit --org
scope; personal Codespaces secrets use --user. Body/title/field values remain
unchanged even when they resemble flags or URLs. Public API absolute URLs use
api.github.com; relative API endpoints remain supported.
Switching account, credential, host or interface invalidates earlier identity
evidence. Recheck before the next write; do not reuse a prior session's pass.
Reference examples show native gh operation syntax. Execute hosted-state
mutations by passing those arguments after the helper's --, with an explicit
repository or account scope; bare gh remains suitable for readback and
separately authorized authentication/configuration. When a builtin's operand
shape is rejected, use its supported explicit REST/GraphQL equivalent through
the same helper; do not bypass the actor check. A failed or timed-out invocation
does not prove the mutation was absent: read the exact target before retrying.
For incident attribution, preserve event ID/time, actor and interface separately
from the ChatGPT execution account. A comment author's login and
performed_via_github_app establish GitHub actor/application, not the ChatGPT
email. A session's creator identity and today's auth file do not establish its
historical execution account. Keep missing links unknown.
Use GitHub-hosted state, not a stale local ref or remembered setting. Capture only the fields required to prove the requested transition. Before a consequential write, make this plan explicit:
Target: fully qualified repository, organization, PR, issue, run, or account
Current: authoritative fields and immutable IDs/SHAs
Requested: exact field or state transition
Blast radius: people, repositories, forks, runs, or public surfaces affected
Recovery: exact inverse operation or explicit “not recoverable”
Readback: independent GET/CLI query and expected resultIf the user already authorized this exact consequence, execute it. Do not add a ceremonial second confirmation. If target, scope, public exposure, deletion, recipient, or recovery remains ambiguous, pause before the write.
Prefer, in order:
gh subcommand;Response fields are not automatically writable fields. Before using PATCH, compare
the desired key against the operation's current request body parameters, not the
shape returned by GET. GitHub may ignore an unsupported key while still returning a
successful response. Do not switch API families merely to make the command run.
Use explicit methods with gh api. Adding -f or -F changes the default method to
POST; filtered GET requests must include -X GET.
xargs command.Run a fresh read that does not trust the mutation response or a cached local ref:
| Mutation | Required acceptance evidence |
|---|---|
| PR merge/close/edit | PR state plus accepted behavior on the fetched base when landing matters |
| Branch deletion | Hosted branch/ref is absent; local remote-tracking cleanup is a separate check |
| Issue/comment/review | Exact object exists once with the intended state/content |
| Repository create/edit/visibility | Fully qualified repository readback matches owner, visibility, and requested fields |
| Collaborator/team permission | Invitation state if pending, then effective permission; also identify remaining base/team grants when revoking |
| Organization setting | A fresh organization/settings read returns every requested field; UI-only settings require UI readback plus any available API signal |
| 2FA requirement | Preflight affected accounts, UI confirmation, API readback, then membership/outside-collaborator audit |
| Workflow dispatch/rerun/cancel | The intended run ID reaches the expected state; command acceptance is not completion |
| Secret/variable change | Metadata and consumer behavior, never secret value disclosure |
For asynchronous state, poll with a bounded deadline and report pending if the terminal
state is not observed. If readback differs, report failed/no-op or partially applied,
show the mismatched fields, and keep recovery available. Never say “done” from the write
receipt alone.
End with one of four honest states:
Authentication is scoped to the authorized operation; it is not a reason to reopen an already-authorized exact write. Before starting an interactive browser or device flow, state the GitHub application, active account, target host, and the exact permission delta. Continue the steps the browser can complete after that explanation. Hand control to the user only when their physical presence is required, such as MFA, a hardware key, or an account-selection decision. Never request broader scopes, a different account, or an unrelated approval merely because the normal flow is interactive.
Do not expose credential values in terminal output, URLs, arguments, committed files, or
reports. A production host's pull-only registry credential is not authorization to publish.
Reuse the current, already-authorized credential when it has been verified for the exact write;
use a temporary local Docker configuration and remove that configuration after the operation.
GHCR publication has its own preflight and digest readback; load
references/ghcr_publishing.md before building or pushing an image.
OWNER/REPO and visibility. Never default
a generic example to --public; public exposure is a product decision.gh repo edit --visibility ... --accept-visibility-change-consequences
only after the consequences and exact repository are authorized, then read back.HOST
explicitly and report when a lower layer cannot change the enforced state.gh pr list -R OWNER/REPO --state open --json number,title,state,url
gh pr view 123 -R OWNER/REPO --json number,title,state,headRefOid,baseRefOid,url
gh issue list -R OWNER/REPO --state open --json number,title,state,url
gh workflow list -R OWNER/REPO
gh run list -R OWNER/REPO --limit 20 \
--json databaseId,status,conclusion,headSha,url
gh api -X GET 'repos/OWNER/REPO/branches?per_page=100' --paginate --jq '.[].name'Use --json/--jq for decisions. Human-formatted output is for reading, not parsing.
© daymade, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 11 other files (scripts, references) in github-ops of daymade/claude-code-skills.
Open the folder on GitHubat commit 91bed2b
GitHub Ops next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Ops this skilldaymade/claude-code-skills | 1.4k | — | ~3.8k | Automated safety check: Pass | MIT | |
| Review PR Commentslatitude-dev/latitude-llm | 4.7k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Gh QueueLanternOps/breeze | 131 | — | ~5k | Automated safety check: Pass | AGPL-3.0 | |
| Reply To PR Threadstobihagemann/turbo | 407 | — | ~941 | Automated safety check: Pass | MIT | |
| Create Cuda Python Pull RequestNVIDIA/cuda-python | 3.4k | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Flow Next Resolve PRgmickel/flow-next | 707 | — | ~1.1k | Automated safety check: Pass | MIT |
latitude-dev/latitude-llm
Triages a PR with GitHub CLI: loads issue-level and inline review feedback (gh pr view, gh api REST, gh api graphql as appropriate), walks items in order, replies in the correct thread, optional…
LanternOps/breeze
A skill your agent uses when reviewing, triaging, or managing the incoming GitHub backlog on the Breeze repo — PRs, Discussions, AND Issues.
tobihagemann/turbo
Draft, confirm, and post replies to GitHub PR review threads.
NVIDIA/cuda-python
Create a CUDA Python pull request from an approved personal or organization-owned fork, including the GitHub CLI GraphQL fallback for renamed organization-owned forks.
gmickel/flow-next
Resolve PR review feedback. An agent skill from gmickel/flow-next.
ayutaz/piper-plus
PR 作成直後の review チェック / 全 open PR の未解決 review thread (isResolved=false) を gh api graphql で集計し、 N 日以上未対応のものを backlog として表示する。
daymade/claude-code-skills
This skill should be used when comparing two videos to analyze compression results or quality differences.
daymade/claude-code-skills
Generates professional animated CLI demos as GIFs using VHS terminal recordings.
daymade/claude-code-skills
Converts DOCX/PDF/PPTX and saved HTML/HTM to high-quality Markdown with automatic post-processing.
daymade/claude-code-skills
Generates several distinct, clickable HTML interaction prototypes for one product surface into a Design Board and collects selection/remix feedback before implementation.
daymade/claude-code-skills
Diagnoses and repairs repository setup and guarded Git workflows for Claude Code or Codex — environment repair, startup sync, hook auditing, collaborator handoff.
daymade/claude-code-skills
Pulls Bigdata.com (RavenPack) financial and news data via the official bigdata-client SDK and /v1/ REST endpoints — structured financials, prices, analyst estimates, entity-sentiment series…
Categories
Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback. GitHub Ops is an agent skill from daymade/claude-code-skills. Operates GitHub via gh CLI and REST/GraphQL — PRs, issues, Actions, repos, collaborators, org permissions, 2FA — with explicit target, authorization, and independent readback.
GitHub Ops fits situations like: A write reports success but state didnt change; choosing gh/REST/GraphQL/UI-only.
Run `npx skills add daymade/claude-code-skills --skill github-ops -a claude-code`. Or copy the skill folder (github-ops in daymade/claude-code-skills) into .claude/skills/github-ops in your project. Claude Code loads it when a task matches its description.
Run `npx skills add daymade/claude-code-skills --skill github-ops -a codex`. Or copy the skill folder (github-ops in daymade/claude-code-skills) into .agents/skills/github-ops in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add daymade/claude-code-skills --skill github-ops -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-ops, .gemini/skills/github-ops, .github/skills/github-ops and .opencode/skills/github-ops in your project.
Going by SKILL.md and its folder, GitHub Ops needs Python for the scripts in its folder and the command-line tools its instructions call (gh and uv). Our summary lists: Python 3; Docker.
SKILL.md contains no URLs. Its commands use gh and uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
GitHub Ops is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 32k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with GitHub Ops: Review PR Comments (latitude-dev/latitude-llm, 4.7k stars), Gh Queue (LanternOps/breeze, 131 stars), Reply To PR Threads (tobihagemann/turbo, 407 stars) and Create Cuda Python Pull Request (NVIDIA/cuda-python, 3.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
daymade (a GitHub user) maintains it in daymade/claude-code-skills, which has 1,444 GitHub stars. The repository holds 103 skills in this directory. The repository was last updated on October 8, 2026.
Source: daymade/claude-code-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.